← Back

Yourls

yourls

Vendor: Yourls • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yourls
1Yourls
Jun 17, 2026
Apr 3, 2022
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.
1Yourls
1Yourls
Jun 17, 2026
Sep 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Yourls
1Yourls
Jun 17, 2026
Sep 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Yourls
1Yourls
Jun 17, 2026
Aug 26, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames
1Yourls
1Yourls
Jun 17, 2026
Oct 23, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multi...Show more
Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.Show less
1Yourls
1Yourls
Jun 17, 2026
Aug 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
2Fedoraproject
Yourls
2Fedora
Yourls
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the administrator panel in Yourls 1.7 allows remote attackers to inject arbitrary web script or HTML via a URL that is processed by the Shorten functionality.
1Yourls
1Yourls
Apr 29, 2026
Sep 24, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Your Own URL Shortener (YOURLS) 1.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/auth.p...Show more
Your Own URL Shortener (YOURLS) 1.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/auth.php and certain other files.Show less