PatchSiren

bg5sbk CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM bg5sbk CVE published 2026-01-05

CVE-2025-15457

A vulnerability was found in bg5sbk MiniCMS up to 1.8, affecting the Trash File Restore Handler in /minicms/mc-admin/post.php. The vulnerability results in improper authentication, allowing remote attacks. The exploit has been made public and could be used. Defenders should assess their exposure and verify authentication mechanisms. This vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. The [truncated]

MEDIUM bg5sbk CVE published 2026-01-05

CVE-2025-15456

A vulnerability exists in bg5sbk MiniCMS versions up to 1.8, specifically in the Publish Page Handler of /mc-admin/page-edit.php, leading to improper authentication. The attack can be performed remotely. However, the existence of this vulnerability is disputed. The vendor, 1234n, was contacted but did not respond. This issue may impact organizations using affected versions, requiring verification of user [truncated]

MEDIUM bg5sbk CVE published 2026-01-05

CVE-2025-15455

A flaw in bg5sbk MiniCMS up to 1.8 allows remote attackers to manipulate the delete_page function in /minicms/mc-admin/page.php, leading to improper authentication. The CVE record was published on 2026-01-05T04:15:41.600Z and was last modified on 2026-09-30T23:10:00.237Z. The NVD entry is currently Analyzed. The vulnerability impacts MiniCMS installations, particularly those using versions up to 1.8, and [truncated]