← All CVEs

CVE-2018-14716

high · 7.5

A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.

7.5
CVSS
33.0%
EPSS (exploit prob.)
98th
EPSS percentile
2018-08-06
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
nystudio107seomatic< 3.1.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-14716