metinfo CVE Vulnerabilities & Metrics

Focus on metinfo vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About metinfo Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with metinfo. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total metinfo CVEs: 52
Earliest CVE date: 01 Nov 2011, 22:55 UTC
Latest CVE date: 07 Dec 2022, 03:15 UTC

Latest CVE reference: CVE-2022-44849

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical metinfo CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.6

Max CVSS: 9.3

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 5
4.0-6.9 37
7.0-8.9 10
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS metinfo CVEs

These are the five CVEs with the highest CVSS scores for metinfo, sorted by severity first and recency.

All CVEs for metinfo

CVE-2022-44849 metinfo vulnerability CVSS: 0 07 Dec 2022, 03:15 UTC

A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account.

CVE-2022-23335 metinfo vulnerability CVSS: 7.5 14 Feb 2022, 21:15 UTC

Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter.

CVE-2022-22295 metinfo vulnerability CVSS: 7.5 14 Feb 2022, 21:15 UTC

Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para parameter.

CVE-2020-20600 metinfo vulnerability CVSS: 3.5 22 Dec 2021, 23:15 UTC

MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.

CVE-2020-21127 metinfo vulnerability CVSS: 7.5 15 Sep 2021, 17:15 UTC

MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.

CVE-2020-21126 metinfo vulnerability CVSS: 6.8 15 Sep 2021, 17:15 UTC

MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.

CVE-2020-20981 metinfo vulnerability CVSS: 5.0 12 Aug 2021, 15:15 UTC

A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database information.

CVE-2020-19305 metinfo vulnerability CVSS: 7.5 03 Aug 2021, 22:15 UTC

An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.

CVE-2020-19304 metinfo vulnerability CVSS: 5.0 03 Aug 2021, 22:15 UTC

An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information.

CVE-2020-18175 metinfo vulnerability CVSS: 7.5 30 Jul 2021, 14:15 UTC

SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php.

CVE-2020-18157 metinfo vulnerability CVSS: 6.8 30 Jul 2021, 14:15 UTC

Cross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php.

CVE-2020-21133 metinfo vulnerability CVSS: 7.5 12 Jul 2021, 13:15 UTC

SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.

CVE-2020-21132 metinfo vulnerability CVSS: 7.5 12 Jul 2021, 13:15 UTC

SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.

CVE-2020-21131 metinfo vulnerability CVSS: 6.5 12 Jul 2021, 13:15 UTC

SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.

CVE-2020-20585 metinfo vulnerability CVSS: 5.0 08 Jul 2021, 16:15 UTC

A blind SQL injection in /admin/?n=logs&c=index&a=dode of Metinfo 7.0 beta allows attackers to access sensitive database information.

CVE-2020-21517 metinfo vulnerability CVSS: 4.3 21 Jun 2021, 15:15 UTC

Cross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php.

CVE-2020-20907 metinfo vulnerability CVSS: 6.4 24 May 2021, 18:15 UTC

MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php.

CVE-2020-20800 metinfo vulnerability CVSS: 7.5 30 Sep 2020, 18:15 UTC

An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the install/index.php?action=adminsetup&cndata=yes&endata=yes&showdata=yes URI.

CVE-2019-17676 metinfo vulnerability CVSS: 6.8 17 Oct 2019, 13:15 UTC

app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI.

CVE-2019-17553 metinfo vulnerability CVSS: 7.5 14 Oct 2019, 13:15 UTC

An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.

CVE-2019-17419 metinfo vulnerability CVSS: 6.5 10 Oct 2019, 01:06 UTC

An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id parameter.

CVE-2019-17418 metinfo vulnerability CVSS: 6.5 10 Oct 2019, 01:06 UTC

An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter, a different issue than CVE-2019-16997.

CVE-2019-16997 metinfo vulnerability CVSS: 6.5 30 Sep 2019, 13:15 UTC

In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.

CVE-2019-16996 metinfo vulnerability CVSS: 6.5 30 Sep 2019, 13:15 UTC

In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.

CVE-2019-13969 metinfo vulnerability CVSS: 6.5 19 Jul 2019, 06:15 UTC

Metinfo 6.x allows SQL Injection via the id parameter in an admin/index.php?n=ui_set&m=admin&c=index&a=doget_text_content&table=lang&field=1 request.

CVE-2017-12789 metinfo vulnerability CVSS: 6.8 10 May 2019, 15:29 UTC

Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state.

CVE-2017-12790 metinfo vulnerability CVSS: 4.3 09 May 2019, 17:29 UTC

Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/index.php. The attack vector is: The administrator clicks on the malicious link in the login state.

CVE-2017-12788 metinfo vulnerability CVSS: 4.3 09 May 2019, 15:29 UTC

Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in Metinfo 5.3.18 allows remote attackers to inject arbitrary web script or HTML via the (1) class1 parameter or the (2) anyid parameter.

CVE-2019-7718 metinfo vulnerability CVSS: 6.8 11 Feb 2019, 04:29 UTC

An issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup function to execute arbitrary PHP code via admin/index.php?n=databack&c=index&a=dogetsql&tables=<?php and admin/databack/bakup_tables.php?2=file_put_contents URIs because app/system/databack/admin/index.class.php creates bakup_tables.php temporarily.

CVE-2018-20486 metinfo vulnerability CVSS: 4.3 26 Dec 2018, 19:29 UTC

MetInfo 6.x through 6.1.3 has XSS via the /admin/login/login_check.php url_array[] parameter.

CVE-2018-19836 metinfo vulnerability CVSS: 4.3 03 Dec 2018, 19:29 UTC

In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example, be exploited in conjunction with CVE-2018-19835 to bypass many XSS filters such as the Chrome XSS filter.

CVE-2018-19835 metinfo vulnerability CVSS: 4.3 03 Dec 2018, 19:29 UTC

Metinfo 6.1.3 has reflected XSS via the admin/column/move.php lang_columnerr4 parameter.

CVE-2018-19051 metinfo vulnerability CVSS: 4.3 07 Nov 2018, 04:29 UTC

MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter.

CVE-2018-19050 metinfo vulnerability CVSS: 4.3 07 Nov 2018, 04:29 UTC

MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword langset parameter.

CVE-2018-18374 metinfo vulnerability CVSS: 3.5 16 Oct 2018, 01:29 UTC

XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.

CVE-2018-18296 metinfo vulnerability CVSS: 4.3 15 Oct 2018, 02:29 UTC

MetInfo 6.1.2 has XSS via the /admin/index.php bigclass parameter in an n=column&a=doadd action.

CVE-2018-17129 metinfo vulnerability CVSS: 4.0 17 Sep 2018, 04:29 UTC

MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field.

CVE-2018-14420 metinfo vulnerability CVSS: 6.8 20 Jul 2018, 01:29 UTC

MetInfo 6.0.0 allows a CSRF attack to add a user account via a doaddsave action to admin/index.php, as demonstrated by an admin/index.php?anyid=47&n=admin&c=admin_admin&a=doaddsave URI.

CVE-2018-14419 metinfo vulnerability CVSS: 3.5 20 Jul 2018, 01:29 UTC

MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.

CVE-2018-13024 metinfo vulnerability CVSS: 6.5 29 Jun 2018, 17:29 UTC

Metinfo v6.0.0 allows remote attackers to write code into a .php file, and execute that code, via the module parameter to admin/column/save.php in an editor upload action.

CVE-2018-12531 metinfo vulnerability CVSS: 7.5 18 Jun 2018, 14:29 UTC

An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into config_db.php, a different vulnerability than CVE-2018-7271.

CVE-2018-12530 metinfo vulnerability CVSS: 5.8 18 Jun 2018, 14:29 UTC

An issue was discovered in MetInfo 6.0.0. admin/app/batch/csvup.php allows remote attackers to delete arbitrary files via a flienamecsv=../ directory traversal. This can be exploited via CSRF.

CVE-2018-9985 metinfo vulnerability CVSS: 4.3 10 Apr 2018, 18:29 UTC

The front page of MetInfo 6.0 allows XSS by sending a feedback message to an administrator.

CVE-2018-9934 metinfo vulnerability CVSS: 4.3 10 Apr 2018, 07:29 UTC

The reset-password feature in MetInfo 6.0 allows remote attackers to change arbitrary passwords via vectors involving a Host HTTP header that is modified to specify a web server under the attacker's control.

CVE-2018-9928 metinfo vulnerability CVSS: 4.3 10 Apr 2018, 06:29 UTC

Cross-site scripting (XSS) vulnerability in save.php in MetInfo 6.0 allows remote attackers to inject arbitrary web script or HTML via the webname or weburl parameter.

CVE-2018-7721 metinfo vulnerability CVSS: 4.3 07 Mar 2018, 08:29 UTC

Cross Site Scripting (XSS) exists in MetInfo 6.0.0 via /feedback/index.php because app/system/feedback/web/feedback.class.php mishandles input data.

CVE-2018-7271 metinfo vulnerability CVSS: 9.3 21 Feb 2018, 00:29 UTC

An issue was discovered in MetInfo 6.0.0. In install/install.php in the installation process, the config/config_db.php configuration file filtering is not rigorous: one can insert malicious code in the installation process to execute arbitrary commands or obtain a web shell.

CVE-2017-14513 metinfo vulnerability CVSS: 5.0 17 Sep 2017, 21:29 UTC

Directory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file via the f_filename parameter in a fingerprintdo action to admin/app/physical/physical.php.

CVE-2017-11500 metinfo vulnerability CVSS: 5.0 20 Jul 2017, 22:29 UTC

A directory traversal vulnerability exists in MetInfo 5.3.17. A remote attacker can use ..\ to delete any .zip file via the filenames parameter to /admin/system/database/filedown.php.

CVE-2017-9764 metinfo vulnerability CVSS: 4.3 19 Jul 2017, 12:29 UTC

Cross-site scripting (XSS) vulnerability in MetInfo 5.3.17 allows remote attackers to inject arbitrary web script or HTML via the Client-IP or X-Forwarded-For HTTP header to /include/stat/stat.php in a para action.

CVE-2017-11347 metinfo vulnerability CVSS: 6.5 17 Jul 2017, 13:18 UTC

Authenticated Code Execution Vulnerability in MetInfo 5.3.17 allows a remote authenticated attacker to generate a PHP script with the content of a malicious image, related to admin/include/common.inc.php and admin/app/physical/physical.php.

CVE-2017-6878 metinfo vulnerability CVSS: 3.5 27 Mar 2017, 15:59 UTC

Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows remote authenticated users to inject arbitrary web script or HTML via the name_2 parameter to admin/column/delete.php.

CVE-2010-4976 metinfo vulnerability CVSS: 4.3 01 Nov 2011, 22:55 UTC

Cross-site scripting (XSS) vulnerability in search/search.php in MetInfo 3.0 allows remote attackers to inject arbitrary web script or HTML via the searchword parameter (aka Search Box field). NOTE: some of these details are obtained from third party information.