Metasoft's vulnerability profile concentrates in its MetaCRM product, a niche but prominent application where disclosed flaws skew strongly toward critical-severity outcomes. The recurring weakness classes—improper access control, unrestricted file uploads, unsafe deserialization, information exposure, and authentication failures—reflect the authentication and data-handling demands of a customer-relationship-management platform and present a material risk to organizations relying on this software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Metasoft over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-7876CRITICAL A vulnerability classified as critical was found in Metasoft 美特软件 MetaCRM up to 6.4.2. This vulnerability affects the function AnalyzeParam of the file download.jsp. The manipulati | Jul 20, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-7873CRITICAL A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file mcc_login.j | Jul 20, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-7879CRITICAL A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the file mobileupload. | Jul 20, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-7877CRITICAL A vulnerability, which was classified as critical, has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This issue affects some unknown processing of the file sendfile.jsp. The man | Jul 20, 2025 | 9.8 | 24 | NO | NO |
CVE-2025-7874CRITICAL A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /env.jsp. The man | Jul 20, 2025 | 9.1 | 24 | NO | NO |
CVE-2025-7878HIGH A vulnerability, which was classified as critical, was found in Metasoft 美特软件 MetaCRM up to 6.4.2. Affected is an unknown function of the file /common/jsp/upload2.jsp. The manipula | Jul 20, 2025 | 8.8 | 22 | NO | NO |
CVE-2025-7875HIGH A vulnerability classified as critical has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This affects an unknown part of the file /debug.jsp. The manipulation leads to improper | Jul 20, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-7880HIGH A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this issue is some unknown functionality of the file /business/common/sms/sen | Jul 20, 2025 | 8.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Metasoft.
Media articles that mention a CVE ID that affects a product developed by Metasoft — matched by CVE ID, not by vendor name.