CVE-2026-29014

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:metinfo:metinfo:7.9:*:*:*:*:*:*:*
cpe:2.3:a:metinfo:metinfo:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:metinfo:metinfo:8.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-01 13:16

Updated : 2026-06-17 10:29


NVD link : CVE-2026-29014

Mitre link : CVE-2026-29014

CVE.ORG link : CVE-2026-29014


JSON object : View

Products Affected

metinfo

  • metinfo
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')