VYPR

SEOmatic

by Craftcms

Source repositories

CVEs (2)

  • CVE-2021-41749CriJun 12, 2022
    risk 0.58cvss 9.8epss 0.18

    In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.

  • CVE-2021-41750MedJun 12, 2022
    risk 0.33cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inject arbitrary web script via a GET to /index.php?action=seomatic/file/seo-file-link with url parameter containing the base64 encoded URL of a malicious web page…