{"id":"CVE-2020-9757","aliases":["GHSA-6q4j-8pjm-5mgc"],"url":"https://o3.security/vulnerability/CVE-2020-9757","summary":"SEOmatic for CraftCMS allows Server-Side Template Injection","details":"The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.","published":"2020-03-04T17:15:12.157Z","modified":"2026-08-07T17:28:01.196688Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.72821,"percentile":0.99423,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"nystudio107/craft-seomatic","fixedVersion":"3.3.0"}],"fix":{"url":"https://github.com/nystudio107/craft-seomatic/commit/65ab659cb6c914c7ad671af1e417c0da2431f79b","label":"nystudio107/craft-seomatic@65ab659"},"references":[{"type":"ADVISORY","url":"https://github.com/nystudio107/craft-seomatic/blob/v3/CHANGELOG.md"},{"type":"FIX","url":"https://github.com/nystudio107/craft-seomatic/commit/65ab659cb6c914c7ad671af1e417c0da2431f79b"},{"type":"FIX","url":"https://github.com/nystudio107/craft-seomatic/commit/a1c2cad7e126132d2442ec8ec8e9ab43df02cc0f"},{"type":"EVIDENCE","url":"https://github.com/giany/CVE/blob/master/CVE-2020-9757.txt"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T17:28:01.196688Z"}}