Vulnerability record · CVE-2020-9757 · published 4 March 2020
CVE-2020-9757: SEOmatic for Craft CMS template injection leads to RCE
Craftcms · Craft Cms
The SEOmatic component for Craft CMS before 3.3.0 is vulnerable to server-side template injection through malformed data sent to the metacontainers controller. Because the injected template code is evaluated server-side, the flaw escalates to remote code execution, making it a serious risk for any site running an unpatched version.
Description
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, a public exploit reference, and very high EPSS make this an urgent pre-auth RCE risk.
What it is
The SEOmatic component for Craft CMS before 3.3.0 is vulnerable to server-side template injection through malformed data sent to the metacontainers controller. Because the injected template code is evaluated server-side, the flaw escalates to remote code execution, making it a serious risk for any site running an unpatched version.
Impact
An unauthenticated attacker can execute arbitrary code on the server, leading to full compromise of the Craft CMS host and any data it can reach.
Attack surface
Reached over the network via the metacontainers controller; the CVSS vector shows no privileges or user interaction required, so the endpoint is directly reachable by an unauthenticated attacker.
Exploitation
No CISA KEV listing and no ransomware association, but EPSS is very high (0.728, 99.4th percentile) and public exploit code is referenced, indicating active interest and likely weaponization.
What to do
- Upgrade SEOmatic to 3.3.0 or later immediately; the patch commits are public.
- If immediate upgrade is not possible, restrict or block access to the metacontainers controller endpoint.
- Apply a WAF rule to detect and block template-injection payloads targeting the controller.
- Audit Craft CMS and SEOmatic versions across all environments and confirm no older copies remain.
- Review server logs for prior exploitation attempts against the metacontainers endpoint.
Detection
- Search web logs for requests to the SEOmatic metacontainers controller with unusual or template-like parameters.
- Monitor for unexpected outbound connections or child processes spawned by the web server/PHP process.
- Alert on file writes or command execution originating from the Craft CMS application user.
- Check for unexpected changes to Craft CMS templates or configuration files.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/giany/CVE/blob/master/CVE-2020-9757.txt | ExploitThird Party Advisory |
| https://github.com/nystudio107/craft-seomatic/blob/v3/CHANGELOG.md | Release NotesThird Party Advisory |
| https://github.com/nystudio107/craft-seomatic/commit/65ab659cb6c914c7ad671af1e417c0da2431f79b | PatchThird Party Advisory |
| https://github.com/nystudio107/craft-seomatic/commit/a1c2cad7e126132d2442ec8ec8e9ab43df02cc0f | PatchThird Party Advisory |
| https://github.com/giany/CVE/blob/master/CVE-2020-9757.txt | ExploitThird Party Advisory |
| https://github.com/nystudio107/craft-seomatic/blob/v3/CHANGELOG.md | Release NotesThird Party Advisory |
| https://github.com/nystudio107/craft-seomatic/commit/65ab659cb6c914c7ad671af1e417c0da2431f79b | PatchThird Party Advisory |
| https://github.com/nystudio107/craft-seomatic/commit/a1c2cad7e126132d2442ec8ec8e9ab43df02cc0f | PatchThird Party Advisory |
Track CVE-2020-9757 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-9757), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.