Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-29014

4 месяца назад

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-wqc8-9v27-r965

4 месяца назад

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2026-07542

5 месяцев назад

Уязвимость функции wxAdminLogin() CMS-системы Metinfo, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-29014

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

CVSS3: 9.8
42%
Средний
4 месяца назад
github логотип
GHSA-wqc8-9v27-r965

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

CVSS3: 9.8
42%
Средний
4 месяца назад
fstec логотип
BDU:2026-07542

Уязвимость функции wxAdminLogin() CMS-системы Metinfo, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
42%
Средний
5 месяцев назад

Уязвимостей на страницу