High severity7.5NVD Advisory· Published Aug 6, 2018· Updated Jun 17, 2026
CVE-2018-14716
CVE-2018-14716
Description
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nystudio107/craft-seomaticPackagist | < 3.1.4 | 3.1.4 |
Affected products
2Patches
Vulnerability mechanics
References
10- github.com/nystudio107/craft-seomatic/releases/tag/3.1.4nvdPatchVendor AdvisoryWEB
- www.exploit-db.com/exploits/45108/nvdExploitThird Party AdvisoryVDB Entry
- ha.cker.info/exploitation-of-server-side-template-injection-with-craft-cms-plguin-seomatic/nvdThird Party Advisory
- github.com/advisories/GHSA-6j9m-rp7m-3gfgghsaADVISORY
- github.com/nystudio107/craft-seomatic/commit/1e7d1d084ac3a89e7ec70620f2749110508d1ce1nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-14716ghsaADVISORY
- twitter.com/nystudio107/status/1021847835418009605nvdVendor AdvisoryWEB
- twitter.com/nystudio107/status/1021855169515057152nvdVendor AdvisoryWEB
- ha.cker.info/exploitation-of-server-side-template-injection-with-craft-cms-plguin-seomaticghsaWEB
- www.exploit-db.com/exploits/45108ghsaWEB
News mentions
0No linked articles in our index yet.