Vulnerabilities (CVE)

Filtered by vendor Metinfo Subscribe
Total 60 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-21517 1 Metinfo 1 Metinfo 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php.
CVE-2020-20585 1 Metinfo 1 Metinfo 2026-07-09 5.0 MEDIUM 7.5 HIGH
A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information.
CVE-2026-29014 1 Metinfo 1 Metinfo 2026-06-17 N/A 9.8 CRITICAL
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.
CVE-2025-63551 1 Metinfo 1 Metinfo 2026-06-17 N/A 7.5 HIGH
A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management System (CMS) thru 8.1. This flaw stems from a defect in the XML parsing logic, which allows an attacker to construct a malicious XML entity that forces the server to initiate an HTTP request to an arbitrary internal or external network address. Successful exploitation could lead to internal network reconnaissance, port scanning, or the retrieval of sensitive information. The vulnerability may be present in the backend API called by or associated with the path `/admin/#/webset/?head_tab_active=0`, where user-provided XML data is processed.
CVE-2025-60454 1 Metinfo 1 Metinfo 2026-06-17 N/A 6.1 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the image management module, specifically in the app\system\img\admin\img_admin.class.php component. The vulnerability allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed by users.
CVE-2025-60453 1 Metinfo 1 Metinfo 2026-06-17 N/A 6.1 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the column management module, specifically in the app\system\column\admin\index.class.php component. The vulnerability allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed by users.
CVE-2025-60452 1 Metinfo 1 Metinfo 2026-06-17 N/A 6.1 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the download management module, specifically in the app\system\download\admin\download_admin.class.php component. The vulnerability allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed by users.
CVE-2025-60451 1 Metinfo 1 Metinfo 2026-06-17 N/A 6.1 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\uploadify.class.php component, specifically in the website settings module. This security flaw allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed.
CVE-2025-60450 1 Metinfo 1 Metinfo 2026-06-17 N/A 6.1 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\editor\Uploader.class.php component. This security flaw allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed.
CVE-2022-44849 1 Metinfo 1 Metinfo 2026-06-17 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account.
CVE-2022-23335 1 Metinfo 1 Metinfo 2026-06-17 7.5 HIGH 9.8 CRITICAL
Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter.
CVE-2022-22295 1 Metinfo 1 Metinfo 2026-06-17 7.5 HIGH 9.8 CRITICAL
Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para parameter.
CVE-2020-21133 1 Metinfo 1 Metinfo 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.
CVE-2020-21132 1 Metinfo 1 Metinfo 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.
CVE-2020-21131 1 Metinfo 1 Metinfo 2026-06-17 6.5 MEDIUM 7.2 HIGH
SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.
CVE-2020-21127 1 Metinfo 1 Metinfo 2026-06-17 7.5 HIGH 9.8 CRITICAL
MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.
CVE-2020-21126 1 Metinfo 1 Metinfo 2026-06-17 6.8 MEDIUM 8.8 HIGH
MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.
CVE-2020-20981 1 Metinfo 1 Metinfo 2026-06-17 5.0 MEDIUM 7.5 HIGH
A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database information.
CVE-2020-20907 2 Metinfo, Microsoft 2 Metinfo, Windows 2026-06-17 6.4 MEDIUM 9.1 CRITICAL
MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php.
CVE-2020-20800 1 Metinfo 1 Metinfo 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes URI.