CVE-2026-29014
CRITICAL EXPLOITED NUCLEIMetInfo CMS 7.9-8.1 - Unauthenticated PHP Code Injection
Title source: manualExploitation Summary
CVE-2026-29014 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including HORKimhab. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains a placeholder markdown file for CVE-2026-29014, describing an unauthenticated PHP code injection RCE in MetInfo CMS versions 7.9, 8.0, and 8.1. However, no actual exploit code, technical details, or proof-of-concept implementation is provided.
Description
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.
Exploits (1)
The repository contains a placeholder markdown file for CVE-2026-29014, describing an unauthenticated PHP code injection RCE in MetInfo CMS versions 7.9, 8.0, and 8.1. However, no actual exploit code, technical details, or proof-of-concept implementation is provided.
Nuclei Templates (1)
http.title:"MetInfo"
app="MetInfo"
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H