{"api_version":"1","generated_at":"2026-07-23T08:47:53+00:00","cve":"CVE-2018-14716","urls":{"html":"https://cve.report/CVE-2018-14716","api":"https://cve.report/api/cve/CVE-2018-14716.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-14716","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-14716"},"summary":{"title":"CVE-2018-14716","description":"A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-08-06 20:29:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-94"],"metrics":[],"references":[{"url":"https://twitter.com/nystudio107/status/1021847835418009605","name":"https://twitter.com/nystudio107/status/1021847835418009605","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"nystudio107 na Twitterze: \"???? PSA: If you're using SEOmatic for Craft CMS 3, I've been alerted to a potential security vulnerability that will be disclosed in the coming days\n\nIt's a bit obtuse, but it was fixed in SEOmatic 3.1.4 & later, so please update, just to be safe! #craftcms https://t.co/Hc7iOPzak3… https://t.co/Hu2l433Faz\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/45108/","name":"45108","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Craft CMS SEOmatic plugin 3.1.4 - Server-Side Template Injection - Linux webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/nystudio107/craft-seomatic/releases/tag/3.1.4","name":"https://github.com/nystudio107/craft-seomatic/releases/tag/3.1.4","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Release Version 3.1.4 · nystudio107/craft-seomatic · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://twitter.com/nystudio107/status/1021855169515057152","name":"https://twitter.com/nystudio107/status/1021855169515057152","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"nystudio107 na Twitterze: \"The researcher in question was awesome, by the way. I'm glad he was responsible and disclosed it to me ahead of time!\n\nHere's my response to his article that he wrote up.… https://t.co/UfhZg8NsHH\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://ha.cker.info/exploitation-of-server-side-template-injection-with-craft-cms-plguin-seomatic/","name":"http://ha.cker.info/exploitation-of-server-side-template-injection-with-craft-cms-plguin-seomatic/","refsource":"MISC","tags":["Third Party Advisory"],"title":"Exploitation of Server Side Template Injection with Craft CMS plugin SEOmatic  | Can I Haz Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/nystudio107/craft-seomatic/commit/1e7d1d084ac3a89e7ec70620f2749110508d1ce1","name":"https://github.com/nystudio107/craft-seomatic/commit/1e7d1d084ac3a89e7ec70620f2749110508d1ce1","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Changed the way requests that don't match any elements generate the `… · nystudio107/craft-seomatic@1e7d1d0 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-14716","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-14716","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"14716","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nystudio107","cpe5":"seomatic","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"craft_cms","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"14716","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nystudio107","cpe5":"seomatic","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"craft_cms","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-14716","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"45108","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/45108/"},{"name":"https://github.com/nystudio107/craft-seomatic/releases/tag/3.1.4","refsource":"CONFIRM","url":"https://github.com/nystudio107/craft-seomatic/releases/tag/3.1.4"},{"name":"https://twitter.com/nystudio107/status/1021855169515057152","refsource":"CONFIRM","url":"https://twitter.com/nystudio107/status/1021855169515057152"},{"name":"http://ha.cker.info/exploitation-of-server-side-template-injection-with-craft-cms-plguin-seomatic/","refsource":"MISC","url":"http://ha.cker.info/exploitation-of-server-side-template-injection-with-craft-cms-plguin-seomatic/"},{"name":"https://twitter.com/nystudio107/status/1021847835418009605","refsource":"CONFIRM","url":"https://twitter.com/nystudio107/status/1021847835418009605"},{"name":"https://github.com/nystudio107/craft-seomatic/commit/1e7d1d084ac3a89e7ec70620f2749110508d1ce1","refsource":"CONFIRM","url":"https://github.com/nystudio107/craft-seomatic/commit/1e7d1d084ac3a89e7ec70620f2749110508d1ce1"}]}},"nvd":{"publishedDate":"2018-08-06 20:29:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-94"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nystudio107:seomatic:*:*:*:*:*:craft_cms:*:*","versionEndExcluding":"3.1.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"14716","Ordinal":"131424","Title":"CVE-2018-14716","CVE":"CVE-2018-14716","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"14716","Ordinal":"1","NoteData":"A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"14716","Ordinal":"2","NoteData":"2018-08-06","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"14716","Ordinal":"3","NoteData":"2018-08-06","Type":"Other","Title":"Modified"}]}}}