← Back to CVE List

CVE-2018-14716

Published: 2018-08-06T20:29Z
Last Modified: 2024-11-21T03:49Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt