{"cve":{"cve_id":"CVE-2025-15458","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.00511,"epss_percentile":0.39503,"epss_as_of":"2026-06-23","description":"A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Article Handler. Executing a manipulation can lead to improper authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.","published_at":"2026-01-05T05:02:06.060000Z","last_modified_at":null,"cvss_v3_score":7.3,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","cvss_v3_severity":"HIGH","cvss_v4_score":6.9,"cvss_v4_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","cvss_v4_severity":"MEDIUM","ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":["CWE-287"],"nvd_references":["https://vuldb.com/?id.339491","https://vuldb.com/?ctiid.339491","https://vuldb.com/?submit.725142","https://github.com/ueh1013/VULN/issues/9"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-28T23:25:30.398979Z"},"effective_severity":"MEDIUM","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"L","value_label":"Low"},{"metric":"I","name":"Integrity","value":"L","value_label":"Low"},{"metric":"A","name":"Availability","value":"L","value_label":"Low"},{"metric":"E","name":"E","value":"P","value_label":"Physical"},{"metric":"RL","name":"RL","value":"X","value_label":"X"},{"metric":"RC","name":"RC","value":"R","value_label":"Required"}]},"cvss_v4_decoded":{"version":"4.0","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"AT","name":"Attack Requirements","value":"N","value_label":"None"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"VC","name":"Confidentiality (Vulnerable System)","value":"L","value_label":"Low"},{"metric":"VI","name":"Integrity (Vulnerable System)","value":"L","value_label":"Low"},{"metric":"VA","name":"Availability (Vulnerable System)","value":"L","value_label":"Low"},{"metric":"SC","name":"Confidentiality (Subsequent System)","value":"N","value_label":"None"},{"metric":"SI","name":"Integrity (Subsequent System)","value":"N","value_label":"None"},{"metric":"SA","name":"Availability (Subsequent System)","value":"N","value_label":"None"},{"metric":"E","name":"E","value":"P","value_label":"Physical"}]},"affected":[{"vendor_slug":"bg5sbk","vendor_name":"bg5sbk","product_slug":"minicms","product_name":"MiniCMS","version_start":"1.0","version_start_inclusive":true,"version_end":"1.0","version_end_inclusive":true,"cpe23_uri":"cve5:bg5sbk:minicms:1.0:1.0"},{"vendor_slug":"bg5sbk","vendor_name":"bg5sbk","product_slug":"minicms","product_name":"MiniCMS","version_start":"1.1","version_start_inclusive":true,"version_end":"1.1","version_end_inclusive":true,"cpe23_uri":"cve5:bg5sbk:minicms:1.1:1.1"},{"vendor_slug":"bg5sbk","vendor_name":"bg5sbk","product_slug":"minicms","product_name":"MiniCMS","version_start":"1.2","version_start_inclusive":true,"version_end":"1.2","version_end_inclusive":true,"cpe23_uri":"cve5:bg5sbk:minicms:1.2:1.2"},{"vendor_slug":"bg5sbk","vendor_name":"bg5sbk","product_slug":"minicms","product_name":"MiniCMS","version_start":"1.3","version_start_inclusive":true,"version_end":"1.3","version_end_inclusive":true,"cpe23_uri":"cve5:bg5sbk:minicms:1.3:1.3"},{"vendor_slug":"bg5sbk","vendor_name":"bg5sbk","product_slug":"minicms","product_name":"MiniCMS","version_start":"1.4","version_start_inclusive":true,"version_end":"1.4","version_end_inclusive":true,"cpe23_uri":"cve5:bg5sbk:minicms:1.4:1.4"},{"vendor_slug":"bg5sbk","vendor_name":"bg5sbk","product_slug":"minicms","product_name":"MiniCMS","version_start":"1.5","version_start_inclusive":true,"version_end":"1.5","version_end_inclusive":true,"cpe23_uri":"cve5:bg5sbk:minicms:1.5:1.5"},{"vendor_slug":"bg5sbk","vendor_name":"bg5sbk","product_slug":"minicms","product_name":"MiniCMS","version_start":"1.6","version_start_inclusive":true,"version_end":"1.6","version_end_inclusive":true,"cpe23_uri":"cve5:bg5sbk:minicms:1.6:1.6"},{"vendor_slug":"bg5sbk","vendor_name":"bg5sbk","product_slug":"minicms","product_name":"MiniCMS","version_start":"1.7","version_start_inclusive":true,"version_end":"1.7","version_end_inclusive":true,"cpe23_uri":"cve5:bg5sbk:minicms:1.7:1.7"},{"vendor_slug":"bg5sbk","vendor_name":"bg5sbk","product_slug":"minicms","product_name":"MiniCMS","version_start":"1.8","version_start_inclusive":true,"version_end":"1.8","version_end_inclusive":true,"cpe23_uri":"cve5:bg5sbk:minicms:1.8:1.8"}],"exploit_refs":[],"news":[],"references":[{"url":"https://vuldb.com/?id.339491","source_type":"MISC","tags":[]},{"url":"https://vuldb.com/?ctiid.339491","source_type":"MISC","tags":[]},{"url":"https://vuldb.com/?submit.725142","source_type":"MISC","tags":[]},{"url":"https://github.com/ueh1013/VULN/issues/9","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2026-01-05T05:02:06.060000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:41:44.930043Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:41:44.930043Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:41:44.930043Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:41:44.930043Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:41:44.930043Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:41:44.930043Z","label":"CVSS score revised","source":"cvelistv5"}]}