Metasoft Metacrm
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Metasoft Metacrm.
By the Year
In 2026 there have been 4 vulnerabilities in Metasoft Metacrm with an average score of 7.1 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4 | 7.05 |
It may take a day or so for new Metacrm vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Metasoft Metacrm Security Vulnerabilities
MetaCRM <6.4.0 Beta06 Unrestricted File Upload /upload.jsp
CVE-2026-16324
7.3 - High
- July 20, 2026
A vulnerability was identified in Metasoft MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Unrestricted File Upload
SQLi via PHPRPC Remote Call in Metasoft MetaCRM 6.4.0 Beta06
CVE-2026-15514
7.3 - High
- July 12, 2026
A weakness has been identified in Metasoft MetaCRM up to 6.4.0 Beta06. This vulnerability affects the function RPCService.query of the file /customizemt/xkq/rpc.jsp of the component PHPRPC Remote Call Interface. Executing a manipulation of the argument phprpc_args can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
SQL Injection
Remote Unrestricted Upload in Metasoft MetaCRM 6.4.0 via upload.jsp
CVE-2026-10205
6.3 - Medium
- June 01, 2026
A security vulnerability has been detected in Metasoft MetaCRM 6.4.0. The impacted element is an unknown function of the file develop/systparam/softlogo/upload.jsp. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Unrestricted File Upload
Metasoft MetaCRM <=6.4.0 beta06 Unrestricted File Upload via upload3.jsp
CVE-2026-8758
7.3 - High
- May 17, 2026
A vulnerability was determined in Metasoft MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Unrestricted File Upload
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Metasoft Metacrm or by Metasoft? Click the Watch button to subscribe.