Vulnerabilities
Vulnerable Software
Yoast:  Security Vulnerabilities
Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.
CVSS Score
5.3
EPSS Score
0.001
Published
2024-06-11
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Yoast Yoast SEO allows Stored XSS.This issue affects Yoast SEO: from n/a through 21.0.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-11-30
Cross-Site Request Forgery (CSRF) vulnerability in Yoast Yoast Local Premium.This issue affects Yoast Local Premium: from n/a through 14.8.
CVSS Score
6.5
EPSS Score
0.002
Published
2023-11-18
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions.
CVSS Score
7.1
EPSS Score
0.001
Published
2023-08-23
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-05-28
A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.
CVSS Score
3.5
EPSS Score
0.002
Published
2022-06-24
The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.
CVSS Score
5.3
EPSS Score
0.274
Published
2022-02-28
The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.
CVSS Score
5.4
EPSS Score
0.004
Published
2021-08-13
The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.
CVSS Score
6.4
EPSS Score
0.001
Published
2021-04-28
A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.
CVSS Score
5.4
EPSS Score
0.003
Published
2021-04-05


Contact Us

Shodan ® - All rights reserved