CVE-2018-14716 describes a Server-Side Template Injection (SSTI) vulnerability in the SEOmatic plugin for Craft CMS, specifically versions prior to 3.1.4. This flaw arises from incorrect canonicalUrl generation for requests that do not match existing elements, allowing for the execution of Twig code. With a CVSS score of 7.5 (High), this vulnerability is remotely exploitable with low attack complexity and requires no user interaction, potentially leading to high confidentiality impact. The EPSS score of 0.60612 indicates a significant likelihood of exploitation. While not listed on the KEV catalog or Hot List, exploit code is publicly available via ExploitDB (EDB-45108). Despite this, there is no evidence of active exploitation, and community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.4CPE matchmatch criteria | cpe:2.3:a:nystudio107:seomatic:*:*:*:*:*:craft_cms:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.