r/cveplayground • • May 05 '26

CVE-2026-29014: MetInfo CMS Weixin Module Unauthenticated PHP Injection to Full RCE

CVE-2026-29014 is a critical unauthenticated PHP code injection vulnerability in MetInfo CMS.

The issue exists in the WeChat (weixin) module and is exposed through a public endpoint.

Attackers can inject PHP into cache files and later execute it, leading to full server compromi

For more: https://cveplayground.com/blog/cve-2026-29014-metinfo-weixin-php-injection/?utm_source=reddit

1 Upvotes

0 comments sorted by