Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-14716

54
FAUCET Score

CVE-2018-14716 describes a Server-Side Template Injection (SSTI) vulnerability in the SEOmatic plugin for Craft CMS, specifically versions prior to 3.1.4. This flaw arises from incorrect canonicalUrl generation for requests that do not match existing elements, allowing for the execution of Twig code. With a CVSS score of 7.5 (High), this vulnerability is remotely exploitable with low attack complexity and requires no user interaction, potentially leading to high confidentiality impact. The EPSS score of 0.60612 indicates a significant likelihood of exploitation. While not listed on the KEV catalog or Hot List, exploit code is publicly available via ExploitDB (EDB-45108). Despite this, there is no evidence of active exploitation, and community discussion and media coverage remain minimal.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.1.4CPE matchmatch criteria
cpe:2.3:a:nystudio107:seomatic:*:*:*:*:*:craft_cms:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
33.03%
Probability of exploitation in next 30 days
EPSS Percentile
98.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-45108 · Jul 31, 2018
This CVE's current EPSS score of 0.3303 is in the 97th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: nystudio107/craft-seomaticFixed in: 3.1.4
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-6j9m-rp7m-3gfghigh

SEOmatic plugin for Craft CMS SSTI Vulnerability

May 13, 2022

References

ha.cker.info / exploitation-of-server-side-template-injection-with-craft-cms-plguin-seomatic
Third Party Advisory
github.com / nystudio107/craft-seomatic/commit/1e7d1d084ac3a89e7ec70620f2749110508d1ce1
Vendor Advisory
github.com / nystudio107/craft-seomatic/releases/tag/3.1.4
PatchVendor Advisory
twitter.com / nystudio107/status/1021847835418009605
Vendor Advisory
twitter.com / nystudio107/status/1021855169515057152
Vendor Advisory
exploit-db.com / exploits/45108
ExploitThird Party AdvisoryVDB Entry