Known Vulnerabilities for products from Metinfo
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Metinfo".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-29014 json | MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attacke... | Not Provided | 2026-04-01 | 2026-04-07 |
| CVE-2022-44849 json | A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Admin... | 8.8 - HIGH | 2022-12-07 | 2022-12-12 |
| CVE-2022-23335 json | Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter. | 9.8 - CRITICAL | 2022-02-14 | 2022-02-22 |
| CVE-2022-22295 json | Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para parame... | 9.8 - CRITICAL | 2022-02-14 | 2022-02-22 |
| CVE-2020-21517 json | Cross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php. | Not Provided | 2021-06-21 | 2026-07-09 |
| CVE-2020-21133 json | SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid. | 9.8 - CRITICAL | 2021-07-12 | 2021-07-12 |
| CVE-2020-21132 json | SQL Injection vulnerability in Metinfo 7.0.0beta in index.php. | 9.8 - CRITICAL | 2021-07-12 | 2021-07-12 |
| CVE-2020-21131 json | SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage. | 7.2 - HIGH | 2021-07-12 | 2021-07-12 |
| CVE-2020-21127 json | MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel. | 9.8 - CRITICAL | 2021-09-15 | 2021-09-23 |
| CVE-2020-21126 json | MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo. | 8.8 - HIGH | 2021-09-15 | 2021-09-23 |
| CVE-2020-20981 json | A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database... | 7.5 - HIGH | 2021-08-12 | 2021-08-16 |
| CVE-2020-20907 json | MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/la... | 9.1 - CRITICAL | 2021-05-24 | 2022-10-05 |
| CVE-2020-20800 json | An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes... | 9.8 - CRITICAL | 2020-09-30 | 2020-10-02 |
| CVE-2020-20600 json | MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index... | 5.4 - MEDIUM | 2021-12-22 | 2021-12-23 |
| CVE-2020-20585 json | A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database info... | Not Provided | 2021-07-08 | 2026-07-09 |
| CVE-2020-19305 json | An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the c... | 9.8 - CRITICAL | 2021-08-03 | 2022-10-05 |
| CVE-2020-19304 json | An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory trav... | 7.5 - HIGH | 2021-08-03 | 2021-08-11 |
| CVE-2020-18175 json | SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php. | 9.8 - CRITICAL | 2021-07-30 | 2021-08-03 |
| CVE-2020-18157 json | Cross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php. | 8.8 - HIGH | 2021-07-30 | 2021-08-03 |
| CVE-2019-17676 json | app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup acti... | 8.8 - HIGH | 2019-10-17 | 2019-10-21 |
Known software with vulnerabilities from Metinfo
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Metinfo | Metinfo | 1.0 |