CVE-2026-29014 PUBLISHED

MetInfo CMS Unauthenticated PHP Code Injection RCE

Assigner: VulnCheck
Reserved: 03.03.2026 Published: 01.04.2026 Updated: 01.04.2026

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor MetInfo CMS
Product MetInfo CMS
Versions Default: unknown
  • affected from 7.9.0 to 8.1.0 (incl.)

Credits

  • Egidio Romano finder

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE