References https://nvd.nist.gov/vuln/detail/CVE-2026-29014 https://thehackernews.com/2026/05/metinfo-cms-cve-2026-29014-exploited.html https://avd.aliyun.com/detail?id=AVD-2026-29014 https://websec.net/blog/cve-2026-29014-metinfo-cms-unauthenticated-php-code-injection-69cdc290c14a8a99e1f91b7a https://ddpoc.com/DVB-2026-11062.html https://cve.imfht.com/intel/573256 https://www.vulncheck.com/advisories/metinfo-cms-unauthenticated-php-code-injection-rce https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-29014.yaml https://www.metinfo.cn/news/2875.html https://cvedetails.com/cve/CVE-2026-29014/
Related VulnerabilitiesMetInfo CMS /app/system/entrance.php 代码执行漏洞(CVE-2026-29014)PoCCVE-2026-29014: MetInfo CMS <= 8.1 - Remote Code ExecutionCVE-2019-16996: Metinfo 7.0.0beta SQL InjectCVE-2019-16997: Metinfo sql injectCVE-2019-17418: Metinfo sql injectPoCCVE-2019-16996: Metinfo 7.0.0 beta - SQL InjectionPoCCVE-2019-16997: Metinfo 7.0.0 beta - SQL InjectionPoCCVE-2019-17418: MetInfo 7.0.0 beta - SQL InjectionPoCCVE-2022-29014: Razer Sila Gaming Router 2.0.441_api-2.0.418 - Local File InclusionPoCCNVD-2018-13393: Metinfo file readPoCCNVD-2018-13393: Metinfo - Local File InclusionPoCmetinfo-file-read: Metinfo file readMetInfo /app/system/entrance.php 任意文件上传漏洞