{"id":"CVE-2021-41749","details":"In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.","aliases":["GHSA-g7xr-v82w-qggq"],"modified":"2026-07-09T01:07:35.370903Z","published":"2022-06-12T11:15:07.663Z","references":[{"type":"ADVISORY","url":"https://github.com/nystudio107/craft-seomatic/blob/develop/CHANGELOG.md"},{"type":"FIX","url":"https://github.com/nystudio107/craft-seomatic/commit/3fee7d50147cdf3f999cfc1e04cbc3fb3d9f2f7d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nystudio107/craft-seomatic","events":[{"introduced":"0"},{"last_affected":"e59c9dde903d21eb2451017f278ef82d9d3534d3"},{"fixed":"3fee7d50147cdf3f999cfc1e04cbc3fb3d9f2f7d"}],"database_specific":{"cpe":"cpe:2.3:a:nystudio107:seomatic:*:*:*:*:*:craft_cms:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.4.11"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["3.4.11","3.4.10","3.4.9","3.4.8","3.4.7","3.4.6","3.4.5","3.4.4","3.4.3","3.4.2","3.4.1","3.4.0","3.3.48","3.0.23","3.0.0-beta.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41749.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}