Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2023-28775

Disclosure Date: June 11, 2024 (last updated August 08, 2024)
Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.
Attacker Value
Unknown

CVE-2024-4984

Disclosure Date: May 16, 2024 (last updated January 05, 2025)
The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ author meta in all versions up to, and including, 22.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown

CVE-2024-4041

Disclosure Date: May 14, 2024 (last updated January 05, 2025)
The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 22.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown

CVE-2023-40680

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Yoast Yoast SEO allows Stored XSS.This issue affects Yoast SEO: from n/a through 21.0.
Attacker Value
Unknown

CVE-2023-28780

Disclosure Date: November 18, 2023 (last updated November 30, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Yoast Yoast Local Premium.This issue affects Yoast Local Premium: from n/a through 14.8.
Attacker Value
Unknown

CVE-2023-32300

Disclosure Date: August 23, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions.
Attacker Value
Unknown

CVE-2023-28785

Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions.
Attacker Value
Unknown

CVE-2021-25118

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.
Attacker Value
Unknown

CVE-2021-36788

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.
Attacker Value
Unknown

CVE-2021-31779

Disclosure Date: April 28, 2021 (last updated February 22, 2025)
The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.