Nystudio107 maintains SEOmatic, a Craft CMS plugin focused on search engine optimization and metadata management, where the observed vulnerability footprint centers on input-handling and output-encoding issues. The recurring weakness classes—code injection, cross-site scripting, and downstream injection—reflect the plugin's role in processing and rendering user-controlled metadata and content within a templating environment. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nystudio107 over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14716HIGH A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the ca | Aug 6, 2018 | 7.5 | 54 | NO | YES |
CVE-2021-41749CRITICAL In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution. | Jun 12, 2022 | 9.8 | 52 | NO | YES |
CVE-2021-44618CRITICAL A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header. | Mar 11, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-41750MEDIUM A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inject arbitrary web script via a GET to /index.php?action=seoma | Jun 12, 2022 | 6.1 | 22 | NO | NO |
CVE-2020-12790HIGH In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template Injection and credentials disclos | May 11, 2020 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nystudio107.
Media articles that mention a CVE ID that affects a product developed by Nystudio107 — matched by CVE ID, not by vendor name.