cbcvebase.

Yoast Seo vulnerabilities

10 known vulnerabilities affecting yoast/yoast_seo.

Total CVEs
10
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM9

Vulnerabilities

Page 1 of 1
CVE-2021-25118P3MEDIUMCVSS 5.3PoC≥ 16.7, < 17.32022-02-28
CVE-2021-25118 [MEDIUM] CWE-200 CVE-2021-25118: The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of f The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.
nvd
CVE-2019-13478P3CRITICALCVSS 9.8fixed in 11.6v11.62019-07-09
CVE-2019-13478 [CRITICAL] CWE-79 CVE-2019-13478: The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in ter The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.
nvd
CVE-2018-19370P3MEDIUMCVSS 6.6≤ 9.2.02018-11-28
CVE-2018-19370 [MEDIUM] CWE-362 CVE-2018-19370: A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.
nvd
CVE-2021-31779P4MEDIUMCVSS 6.4fixed in 7.2.12021-04-28
CVE-2021-31779 [MEDIUM] CWE-918 CVE-2021-31779: The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user accoun The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.
nvd
CVE-2023-28775P4MEDIUMCVSS 5.3fixed in 20.52024-06-11
CVE-2023-28775 [MEDIUM] CWE-862 CVE-2023-28775: Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.
nvd
CVE-2021-24153P4MEDIUMCVSS 5.4fixed in 3.4.12021-04-05
CVE-2021-24153 [MEDIUM] CWE-79 CVE-2021-24153: A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.
nvd
CVE-2023-32300P4MEDIUMCVSS 6.1≤ 14.82023-08-23
CVE-2023-32300 [MEDIUM] CWE-79 CVE-2023-32300: Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions.
nvd
CVE-2021-36788P4MEDIUMCVSS 5.4fixed in 7.2.32021-08-13
CVE-2021-36788 [MEDIUM] CWE-79 CVE-2021-36788: The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS. The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.
nvd
CVE-2023-28785P4MEDIUMCVSS 5.4≤ 14.92023-05-28
CVE-2023-28785 [MEDIUM] CWE-79 CVE-2023-28785: Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugi Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions.
nvd
CVE-2023-40680P4MEDIUMCVSS 4.8≤ 21.02023-11-30
CVE-2023-40680 [MEDIUM] CWE-79 CVE-2023-40680: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Yoast Yoast SEO allows Stored XSS.This issue affects Yoast SEO: from n/a through 21.0.
nvd
Yoast Seo vulnerabilities | cvebase