High severity7.5NVD Advisory· Published May 11, 2020· Updated Jun 17, 2026
CVE-2020-12790
CVE-2020-12790
Description
In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template Injection and credentials disclosure via a crafted Twig template after a semicolon.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nystudio107/craft-seomaticPackagist | < 3.2.49 | 3.2.49 |
Affected products
3- Craft CMS/SEOmatic plugindescription
Patches
Vulnerability mechanics
References
7- github.com/nystudio107/craft-seomatic/commit/82f4a25b28fd622393da6592dc9e5ccee7fc5be3nvdPatchThird Party AdvisoryWEB
- isec.pl/en/vulnerabilities/isec-0028-seomatic-ssti-23032020.txtnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-23q7-59jj-2pj4ghsaADVISORY
- github.com/nystudio107/craft-seomatic/blob/v3/CHANGELOG.mdnvdRelease NotesThird Party AdvisoryWEB
- github.com/nystudio107/craft-seomatic/releases/tag/3.2.49nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-12790ghsaADVISORY
- github.com/nystudio107/craft-seomatic/commit/82f4a25b28fd622393da6592dc9e5ccee7fc5be3ghsaWEB
News mentions
0No linked articles in our index yet.