CVE-2026-29014

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:metinfo:metinfo:7.9:*:*:*:*:*:*:*
cpe:2.3:a:metinfo:metinfo:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:metinfo:metinfo:8.1:*:*:*:*:*:*:*

History

07 Apr 2026, 20:38

Type Values Removed Values Added
First Time Metinfo
Metinfo metinfo
CPE cpe:2.3:a:metinfo:metinfo:7.9:*:*:*:*:*:*:*
cpe:2.3:a:metinfo:metinfo:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:metinfo:metinfo:8.1:*:*:*:*:*:*:*
References () https://karmainsecurity.com/KIS-2026-06 - () https://karmainsecurity.com/KIS-2026-06 - Exploit, Third Party Advisory
References () https://www.metinfo.cn/ - () https://www.metinfo.cn/ - Product
References () https://www.vulncheck.com/advisories/metinfo-cms-unauthenticated-php-code-injection-rce - () https://www.vulncheck.com/advisories/metinfo-cms-unauthenticated-php-code-injection-rce - Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2026/Apr/1 - () http://seclists.org/fulldisclosure/2026/Apr/1 - Mailing List, Third Party Advisory
References () https://websec.net/blog/cve-2026-29014-metinfo-cms-unauthenticated-php-code-injection-69cdc290c14a8a99e1f91b7a - () https://websec.net/blog/cve-2026-29014-metinfo-cms-unauthenticated-php-code-injection-69cdc290c14a8a99e1f91b7a - Exploit, Third Party Advisory

03 Apr 2026, 17:16

Type Values Removed Values Added
References
  • () https://websec.net/blog/cve-2026-29014-metinfo-cms-unauthenticated-php-code-injection-69cdc290c14a8a99e1f91b7a -

03 Apr 2026, 06:16

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2026/Apr/1 -

01 Apr 2026, 16:23

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

01 Apr 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-01 13:16

Updated : 2026-04-07 20:38


NVD link : CVE-2026-29014

Mitre link : CVE-2026-29014

CVE.ORG link : CVE-2026-29014


JSON object : View

Products Affected

metinfo

  • metinfo
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')