{"id":"CVE-2020-9757","details":"The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.","aliases":["GHSA-6q4j-8pjm-5mgc"],"modified":"2026-08-07T17:28:01.196688Z","published":"2020-03-04T17:15:12.157Z","references":[{"type":"ADVISORY","url":"https://github.com/nystudio107/craft-seomatic/blob/v3/CHANGELOG.md"},{"type":"FIX","url":"https://github.com/nystudio107/craft-seomatic/commit/65ab659cb6c914c7ad671af1e417c0da2431f79b"},{"type":"FIX","url":"https://github.com/nystudio107/craft-seomatic/commit/a1c2cad7e126132d2442ec8ec8e9ab43df02cc0f"},{"type":"EVIDENCE","url":"https://github.com/giany/CVE/blob/master/CVE-2020-9757.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/craftcms/cms","events":[{"introduced":"0"},{"fixed":"777b2f0154e998dd1c5ebacf3caffe7f02639ec2"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"3.3.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*"}}],"versions":["3.2.10","3.2.9","3.2.8","3.2.7","3.2.6","3.2.5.1","3.1.34","3.2.0","3.2.5","3.2.4.1","3.2.4","3.2.3","3.2.2","3.2.1","3.1.33","3.1.32.1","3.1.32","3.1.31","3.1.30","3.1.29","3.1.28","3.1.26","3.1.27","3.1.25","3.1.24","3.1.23","3.1.22","3.1.21.1","3.1.21","3.1.20.1","3.1.20","3.1.19","3.1.18","3.1.17.2","3.1.17.1","3.1.17","3.1.16","3.1.15","3.1.14","3.1.13","3.1.12","3.1.11","3.1.10","3.1.9.1","3.1.9","3.1.8","3.1.7","3.1.6.1","3.1.6","3.1.5","3.1.4","3.0.37","3.1.3","3.1.2.2","3.1.2.1","3.1.2","3.1.1","3.0.36","3.0.35","3.0.34","3.0.33","3.0.32","3.0.31","3.0.30.2","3.0.30.1","3.0.30","3.0.29","3.0.28","3.0.27.1","3.0.27","3.0.26.1","3.0.26","3.0.0-RC10.1","3.0.0-alpha.2948","3.0.0-alpha.2942","3.0.0-alpha.2939","3.0.0-alpha.2937","3.0.0-alpha.2933","3.0.0-alpha.2928","3.0.0-alpha.2918","3.0.0-alpha.2915","3.0.0-alpha.2687","3.0.0-alpha.2681","3.0.0-alpha.2671","2.3.2617","2.3.2616","2.3.2615","2.3.0-alpha.2612","2.3.0-alpha.2610","2.3.0-alpha.2608","2.3.0-alpha.2606","2.3.0-alpha.2605","2.3.0-alpha.2603","2.3.0-alpha.2602","2.3.0-alpha.2600","2.2.2581","2.2.2579","2.2.0-alpha.2578","2.1.2557","2.1.2556","2.1.2555","2.1.2554","2.1.0-alpha.2552","2.1.0-alpha.2547","2.1.0-alpha.2546","2.0.2539","2.0.2538","2.0.2537","2.0.2536","2.0.2535","2.0.2533","2.0.2532","2.0.2527","2.0.2525","2.0.2524","1.4.0-alpha.2509","1.4.0-alpha.2505","1.4.0-alpha.2503","1.4.0-alpha.2502","1.4.0-alpha.2500","1.4.0-alpha.2499","1.4.0-alpha.2498","1.4.0-alpha.2497","1.4.0-alpha.2493","1.4.0-alpha.2492","1.4.0-alpha.2491","1.4.0-alpha.2490","1.4.0-alpha.2489","1.4.0-alpha.2488","1.2.2339","1.2.2336","1.2.2335","1.2.2333","1.2.0-alpha.2329","1.2.0-alpha.2328","1.2.0-alpha.2322","1.2.0-alpha.2319","1.2.0-alpha.2318","1.2.0-alpha.2312","1.2.0-alpha.2310","1.1.2291","1.1.0-alpha.2288","1.1.0-alpha.2285","1.1.0-alpha.2284","1.1.0-alpha.2283","1.0.2266","1.0.0-alpha.2249","1.0.0-alpha.2248","1.0.0-alpha.2247","0.9.2246","1.0.0-alpha.2245","1.0.0-alpha.2244","0.9.2243","1.0.0-alpha.2242","1.0.0-alpha.2241","1.0.0-alpha.2238","1.0.0-alpha.2237","1.0.0-alpha.2236","0.9.2193","0.9.2189","0.9.2184","0.9.2181","0.9.2177","0.9.2168","0.9.2167","0.9.2157","0.9.2151","0.9.2146","0.9.2124","0.9.2123","0.9.2117","0.9.2116","0.9.2106","0.9.2102","0.9.2103","0.9.2101","0.9.2100","0.9.2094","0.9.2090","0.9.2083","0.9.2081","0.9.2080","0.9.2079","0.9.2078","0.9.2071","0.9.2068","0.9.2065","0.9.2064","0.9.2063"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-9757.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/nystudio107/craft-seomatic","events":[{"introduced":"0"},{"fixed":"2382fd7fc25acd507122734c0a78d528390e49cd"},{"fixed":"65ab659cb6c914c7ad671af1e417c0da2431f79b"},{"fixed":"a1c2cad7e126132d2442ec8ec8e9ab43df02cc0f"}],"database_specific":{"cpe":"cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.3.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["3.2.51","3.2.50","3.2.49","3.2.48","3.2.47","3.2.46","3.2.45","3.2.44","3.2.43","3.2.42","3.2.41","3.2.39","3.2.38","3.2.37","3.2.36","3.2.35","3.2.34","3.2.33","3.2.32","3.2.31","3.2.30","3.2.29","3.2.28","3.2.27","3.2.26","3.2.25","3.2.24","3.2.23","3.2.22","3.2.21","3.2.20","3.2.19","3.2.18","3.2.17","3.2.16","3.2.15","3.2.14","3.2.13","3.2.12","3.2.11","3.2.10","3.2.9","3.2.8","3.2.7","3.2.6","3.2.5","3.2.4","3.2.3","3.2.2","3.2.1","3.2.0","3.1.50","3.0.23","3.0.0-beta.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-9757.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}