Critical severity9.8NVD Advisory· Published Jun 12, 2022· Updated Jun 17, 2026
CVE-2021-41749
CVE-2021-41749
Description
In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nystudio107/craft-seomaticPackagist | < 3.4.11 | 3.4.11 |
Affected products
3- Craft CMS/SEOmatic plugindescription
Patches
Vulnerability mechanics
References
4- github.com/nystudio107/craft-seomatic/commit/3fee7d50147cdf3f999cfc1e04cbc3fb3d9f2f7dnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-g7xr-v82w-qggqghsaADVISORY
- github.com/nystudio107/craft-seomatic/blob/develop/CHANGELOG.mdnvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-41749ghsaADVISORY
News mentions
0No linked articles in our index yet.