Craft CMS before 3.3.0 is susceptible to server-side template injection via the SEOmatic component that could lead to remote code execution via malformed data submitted to the metacontainers controller.
id: CVE-2020-9757
info:
name: Craft CMS < 3.3.0 - Server-Side Template Injection
author: dwisis
...