← Vulnerability feed

Vulnerability record · CVE-2020-9757 · published 4 March 2020

CVE-2020-9757: SEOmatic for Craft CMS template injection leads to RCE

Craftcms · Craft Cms

The SEOmatic component for Craft CMS before 3.3.0 is vulnerable to server-side template injection through malformed data sent to the metacontainers controller. Because the injected template code is evaluated server-side, the flaw escalates to remote code execution, making it a serious risk for any site running an unpatched version.

9.8 CVSS 3.1 Critical EPSS 73% · top 0.6% CWE-74 · Injection
9.8CVSS 3.1 base score, v2 7.5
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, a public exploit reference, and very high EPSS make this an urgent pre-auth RCE risk.

What it is

The SEOmatic component for Craft CMS before 3.3.0 is vulnerable to server-side template injection through malformed data sent to the metacontainers controller. Because the injected template code is evaluated server-side, the flaw escalates to remote code execution, making it a serious risk for any site running an unpatched version.

Impact

An unauthenticated attacker can execute arbitrary code on the server, leading to full compromise of the Craft CMS host and any data it can reach.

Attack surface

Reached over the network via the metacontainers controller; the CVSS vector shows no privileges or user interaction required, so the endpoint is directly reachable by an unauthenticated attacker.

Exploitation

No CISA KEV listing and no ransomware association, but EPSS is very high (0.728, 99.4th percentile) and public exploit code is referenced, indicating active interest and likely weaponization.

What to do

  • Upgrade SEOmatic to 3.3.0 or later immediately; the patch commits are public.
  • If immediate upgrade is not possible, restrict or block access to the metacontainers controller endpoint.
  • Apply a WAF rule to detect and block template-injection payloads targeting the controller.
  • Audit Craft CMS and SEOmatic versions across all environments and confirm no older copies remain.
  • Review server logs for prior exploitation attempts against the metacontainers endpoint.

Detection

  • Search web logs for requests to the SEOmatic metacontainers controller with unusual or template-like parameters.
  • Monitor for unexpected outbound connections or child processes spawned by the web server/PHP process.
  • Alert on file writes or command execution originating from the Craft CMS application user.
  • Check for unexpected changes to Craft CMS templates or configuration files.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-9757 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32432Craft CMS unauthenticated remote code execution via code injectionCraft CMS versions 3.0.0-RC1 through 3.9.14, 4.0.0-RC1 through 4.14.14, and 5.0.0-RC1 through 5.6.16 contain a code injection flaw enabling remote co…KEVEPSS 100%analysed9.3CVE-2024-56145Craft CMS code injection via register_argc_argv leads to RCECraft CMS contains a code injection flaw (CWE-94) that allows remote code execution when the PHP setting register_argc_argv is enabled. The vendor de…KEVEPSS 97%analysed8.1CVE-2025-23209Craft CMS code injection RCE with compromised security keyCraft CMS 4 and 5 contain a code injection flaw (CWE-94) that allows remote code execution when the installation's security key has already been comp…KEVEPSS 22%analysed6.9CVE-2025-35939Craft CMS unauthenticated session file write enables PHP code injectionCraft CMS stores unsanitized client-supplied return URL values in server-side session files for unauthenticated users. Because the session file path …KEVEPSS 1.3%analysed9.8CVE-2024-37843Craft CMS SQL injection via GraphQL API endpointCraft CMS up to v3.7.31 contains a SQL injection flaw reachable through its GraphQL API endpoint. The CVSS vector indicates the attack is network-rea…EPSS 53%analysed9.8CVE-2023-41892Craft CMS code injection enables unauthenticated remote code executionCraft CMS versions before 4.4.15 contain a code injection flaw (CWE-94) that allows remote code execution. The vendor describes it as a high-impact, …EPSS 94%analysed9.8CVE-2021-27903Craftcms craft cms missing authorization vulnerabilityAn issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did n…EPSS 2.8%9.8CVE-2019-15929Craftcms craft cms weak password recovery vulnerabilityIn Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a …EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2020-9757), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.