In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13339.json"