Vulnerability intelligence
CVE-2026-29014
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
39%
Riskier than 99% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
2 articles across 2 outlets · first covered May 5, 2026 · latest May 5, 2026
Coverage timeline
-
Attackers exploit CVE-2026-29014 to hijack MetInfo CMSthehackernews.com · May 5, 2026
-
MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairswww.securityweek.com · May 5, 2026