Known Vulnerabilities for products from Metinfo

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Metinfo".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-29014 json MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attacke... Not Provided 2026-04-01 2026-04-07
CVE-2022-44849 json A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Admin... 8.8 - HIGH 2022-12-07 2022-12-12
CVE-2022-23335 json Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter. 9.8 - CRITICAL 2022-02-14 2022-02-22
CVE-2022-22295 json Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para parame... 9.8 - CRITICAL 2022-02-14 2022-02-22
CVE-2020-21517 json Cross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php. Not Provided 2021-06-21 2026-07-09
CVE-2020-21133 json SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid. 9.8 - CRITICAL 2021-07-12 2021-07-12
CVE-2020-21132 json SQL Injection vulnerability in Metinfo 7.0.0beta in index.php. 9.8 - CRITICAL 2021-07-12 2021-07-12
CVE-2020-21131 json SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage. 7.2 - HIGH 2021-07-12 2021-07-12
CVE-2020-21127 json MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel. 9.8 - CRITICAL 2021-09-15 2021-09-23
CVE-2020-21126 json MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo. 8.8 - HIGH 2021-09-15 2021-09-23
CVE-2020-20981 json A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database... 7.5 - HIGH 2021-08-12 2021-08-16
CVE-2020-20907 json MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/la... 9.1 - CRITICAL 2021-05-24 2022-10-05
CVE-2020-20800 json An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes... 9.8 - CRITICAL 2020-09-30 2020-10-02
CVE-2020-20600 json MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index... 5.4 - MEDIUM 2021-12-22 2021-12-23
CVE-2020-20585 json A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database info... Not Provided 2021-07-08 2026-07-09
CVE-2020-19305 json An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the c... 9.8 - CRITICAL 2021-08-03 2022-10-05
CVE-2020-19304 json An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory trav... 7.5 - HIGH 2021-08-03 2021-08-11
CVE-2020-18175 json SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php. 9.8 - CRITICAL 2021-07-30 2021-08-03
CVE-2020-18157 json Cross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php. 8.8 - HIGH 2021-07-30 2021-08-03
CVE-2019-17676 json app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup acti... 8.8 - HIGH 2019-10-17 2019-10-21

Known software with vulnerabilities from Metinfo

Type Vendor Product Version
ApplicationMetinfoMetinfo1.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report