VYPR

Metinfo

by Metinfo

Source repositories

CVEs (64)

  • CVE-2025-60452MedOct 3, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the download management module, specifically in the app\system\download\admin\download_admin.class.php component. The vulnerability allows attackers to…

  • CVE-2025-60451MedOct 3, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\uploadify.class.php component, specifically in the…

  • CVE-2025-60450MedOct 3, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG file uploads in the app\system\include\module\editor\Uploader.class.php component. This security flaw…

  • CVE-2020-21517MedJun 21, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php.

  • CVE-2017-12788MedMay 9, 2019
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in Metinfo 5.3.18 allows remote attackers to inject arbitrary web script or HTML via the (1) class1 parameter or the (2) anyid parameter.

  • CVE-2018-20486MedDec 26, 2018
    risk 0.40cvss 6.1epss 0.01

    MetInfo 6.x through 6.1.3 has XSS via the /admin/login/login_check.php url_array[] parameter.

  • CVE-2018-19836MedDec 3, 2018
    risk 0.40cvss 6.1epss 0.01

    In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows registering variables from the $_COOKIE value. This issue can, for example, be exploited in conjunction with CVE-2018-19835 to bypass…

  • CVE-2018-19835MedDec 3, 2018
    risk 0.40cvss 6.1epss 0.01

    Metinfo 6.1.3 has reflected XSS via the admin/column/move.php lang_columnerr4 parameter.

  • CVE-2018-19051MedNov 7, 2018
    risk 0.40cvss 6.1epss 0.01

    MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter.

  • CVE-2018-19050MedNov 7, 2018
    risk 0.40cvss 6.1epss 0.01

    MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword langset parameter.

  • CVE-2018-18296MedOct 15, 2018
    risk 0.40cvss 6.1epss 0.01

    MetInfo 6.1.2 has XSS via the /admin/index.php bigclass parameter in an n=column&a=doadd action.

  • CVE-2018-9985MedApr 10, 2018
    risk 0.40cvss 6.1epss 0.01

    The front page of MetInfo 6.0 allows XSS by sending a feedback message to an administrator.

  • CVE-2018-9928MedApr 10, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in save.php in MetInfo 6.0 allows remote attackers to inject arbitrary web script or HTML via the webname or weburl parameter.

  • CVE-2018-7721MedMar 7, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) exists in MetInfo 6.0.0 via /feedback/index.php because app/system/feedback/web/feedback.class.php mishandles input data.

  • CVE-2017-11718MedJul 28, 2017
    risk 0.40cvss 6.1epss 0.01

    There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.

  • CVE-2017-11716MedJul 28, 2017
    risk 0.40cvss 6.1epss 0.01

    MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.

  • CVE-2017-9764MedJul 19, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in MetInfo 5.3.17 allows remote attackers to inject arbitrary web script or HTML via the Client-IP or X-Forwarded-For HTTP header to /include/stat/stat.php in a para action.

  • CVE-2020-20600MedDec 22, 2021
    risk 0.35cvss 5.4epss 0.01

    MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.

  • CVE-2018-18374MedOct 16, 2018
    risk 0.35cvss 5.4epss 0.01

    XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.

  • CVE-2017-14513MedSep 17, 2017
    risk 0.35cvss 5.3epss 0.02

    Directory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file via the f_filename parameter in a fingerprintdo action to admin/app/physical/physical.php.