CVE-2018-14716: NYSTUDIO107 Seomatic
High severity, CVSS 7.5. EPSS: 33% chance of exploitation in the next 30 days.
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.
Affected products
- NYSTUDIO107 Seomatic: before 3.1.4 (fixed in 3.1.4)
Published 2018-08-06. Last modified 2026-06-17.