Vulnerability index

Browse CVEs

57 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Metinfo CRITICAL 9.8
CVE-2026-29014EPSS 42%

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary …

Mitigation only
Fix from $2,300 2026-04-01
Metinfo HIGH 7.5
CVE-2025-63551

A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management S…

Fix: 8.1+
Fix from $1,950 2025-11-06
Metinfo MEDIUM 6.1
CVE-2025-60454

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the image management mo…

No fix yet
Fix from $1,600 2025-10-03
Metinfo MEDIUM 6.1
CVE-2025-60450

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient valida…

No fix yet
Fix from $1,600 2025-10-03
Metinfo MEDIUM 6.1
CVE-2025-60451

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient valida…

No fix yet
Fix from $1,600 2025-10-03
Metinfo MEDIUM 6.1
CVE-2025-60452

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the download management…

No fix yet
Fix from $1,600 2025-10-03
Metinfo MEDIUM 6.1
CVE-2025-60453

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the column management m…

No fix yet
Fix from $1,600 2025-10-03
Metinfo HIGH 8.8
CVE-2022-44849

A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account.

No fix yet
Fix from $1,950 2022-12-07
Metinfo CRITICAL 9.8
CVE-2022-22295

Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para parameter.

No fix yet
Fix from $2,300 2022-02-14
Metinfo CRITICAL 9.8
CVE-2022-23335

Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter.

No fix yet
Fix from $2,300 2022-02-14
Metinfo MEDIUM 5.4
CVE-2020-20600

MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.

No fix yet
Fix from $1,600 2021-12-22
Metinfo CRITICAL 9.8
CVE-2020-21127

MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.

No fix yet
Fix from $2,300 2021-09-15
Metinfo HIGH 8.8
CVE-2020-21126

MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.

No fix yet
Fix from $1,950 2021-09-15
Metinfo HIGH 7.5
CVE-2020-20981

A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database information.

No fix yet
Fix from $1,950 2021-08-12
Metinfo CRITICAL 9.8
CVE-2020-19305

An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowi…

No fix yet
Fix from $2,300 2021-08-03
Metinfo HIGH 7.5
CVE-2020-19304

An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensiti…

No fix yet
Fix from $1,950 2021-08-03
Metinfo CRITICAL 9.8
CVE-2020-18175

SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php.

No fix yet
Fix from $2,300 2021-07-30
Metinfo HIGH 8.8
CVE-2020-18157

Cross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php.

No fix yet
Fix from $1,950 2021-07-30
Metinfo CRITICAL 9.8
CVE-2020-21132

SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.

No fix yet
Fix from $2,300 2021-07-12
Metinfo CRITICAL 9.8
CVE-2020-21133

SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.

No fix yet
Fix from $2,300 2021-07-12
Metinfo HIGH 7.2
CVE-2020-21131

SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.

No fix yet
Fix from $1,950 2021-07-12
Metinfo HIGH 7.5
CVE-2020-20585

A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information.

No fix yet
Fix from $1,950 2021-07-08
Metinfo MEDIUM 6.1
CVE-2020-21517

Cross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php.

No fix yet
Fix from $1,600 2021-06-21
Metinfo CRITICAL 9.1
CVE-2020-20907

MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_ge…

No fix yet
Fix from $2,300 2021-05-24
Metinfo CRITICAL 9.8
CVE-2020-20800

An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes…

No fix yet
Fix from $2,300 2020-09-30
Metinfo HIGH 8.8
CVE-2019-17676

app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, a…

No fix yet
Fix from $1,950 2019-10-17
Metinfo CRITICAL 9.8
CVE-2019-17553

An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.

No fix yet
Fix from $2,300 2019-10-14
Metinfo HIGH 7.2
CVE-2019-17418EPSS 49%

An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a di…

No fix yet
Fix from $1,950 2019-10-10
Metinfo HIGH 7.2
CVE-2019-17419

An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.

No fix yet
Fix from $1,950 2019-10-10
Metinfo HIGH 7.2
CVE-2019-16996EPSS 12%

In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=d…

No fix yet
Fix from $1,950 2019-09-30