← Back

Yoast Seo

yoast_seo

Vendor: Yoast • 10 CVEs

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yoast
1Yoast Seo
Nov 21, 2024
Jun 11, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.
1Yoast
1Yoast Seo
Apr 28, 2026
Nov 30, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Yoast Yoast SEO allows Stored XSS.This issue affects Yoast SEO: from n/a through 21.0.
1Yoast
1Yoast Seo
Nov 21, 2024
Aug 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions.
1Yoast
1Yoast Seo
Nov 21, 2024
May 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions.
1Yoast
1Yoast Seo
Nov 21, 2024
Feb 28, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities o...Show more
The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.Show less
1Yoast
1Yoast Seo
Nov 21, 2024
Aug 13, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.
1Yoast
1Yoast Seo
Nov 21, 2024
Apr 28, 2021
N/A· v4
6.4 MEDIUM· v3
5.5 MEDIUM· v2
The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.
1Yoast
1Yoast Seo
Nov 21, 2024
Apr 5, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as ale...Show more
A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.Show less
1Yoast
1Yoast Seo
Nov 21, 2024
Jul 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.
1Yoast
1Yoast Seo
Nov 21, 2024
Nov 28, 2018
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operatin...Show more
A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.Show less