ylefebvre records
18 published records for vendor ylefebvre.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 44.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-24875No exploit | WordPress Link Library Plugin <= 7.5.13 is vulnerable to Cross Site Request Forgery (CSRF)ylefebvre · link library · CWE-352 | High8.8 | — | 0.2% | Feb 12, 2024 |
30Monitor | CVE-2021-25093No exploit | Link Library < 7.2.8 - Unauthenticated Arbitrary Links Deletionylefebvre · link library · CWE-862 | High7.5 | — | 1.2% | Feb 1, 2022 |
26Monitor | CVE-2021-25092No exploit | Link Library < 7.2.8 - Library Settings Reset via CSRFylefebvre · link library · CWE-352 | Medium6.5 | — | 0.5% | Feb 1, 2022 |
25Monitor | CVE-2026-18197No exploit | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scriptiylefebvre · link library · CWE-79 | Medium6.4 | — | 0.3% | Jul 29, 2026 |
24Monitor | CVE-2021-25091No exploit | Link Library < 7.2.9 - Reflected Cross-Site Scriptingylefebvre · link library · CWE-79 | Medium6.1 | — | 0.8% | Feb 1, 2022 |
24Monitor | CVE-2024-29123No exploit | WordPress Link Library plugin <= 7.6 - Reflected Cross Site Scripting (XSS) vulnerabilityylefebvre · link library · CWE-79 | Medium6.1 | — | 0.4% | Mar 19, 2024 |
24Monitor | CVE-2024-1559No exploit | Link Library <= 7.6 - Unauthenticated Stored Cross-Site Scriptingylefebvre · link library · CWE-79 | Medium6.1 | — | 0.4% | Feb 20, 2024 |
24Monitor | CVE-2024-2325No exploit | Link Library <= 7.6.6 - Reflected Cross-Site Scriptingylefebvre · link library · CWE-79 | Medium6.1 | — | 0.4% | Apr 9, 2024 |
24Monitor | CVE-2023-31071No exploit | WordPress Modal Dialog Plugin <= 3.5.14 is vulnerable to Cross Site Scripting (XSS)ylefebvre · modal dialog · CWE-79 | Medium6.1 | — | 0.4% | Aug 17, 2023 |
24Monitor | CVE-2024-24879No exploit | WordPress Link Library Plugin <= 7.5.13 is vulnerable to Cross Site Scripting (XSS)ylefebvre · link library · CWE-79 | Medium6.1 | — | 0.4% | Feb 8, 2024 |
24Monitor | CVE-2024-38711No exploit | WordPress Link Library plugin <= 7.7.1 - Reflected Cross Site Scripting (XSS) vulnerabilityylefebvre · link library · CWE-79 | Medium6.1 | — | 0.4% | Jul 20, 2024 |
24Monitor | CVE-2024-35687No exploit | WordPress Link Library plugin <= 7.6.3 - Reflected Cross-Site Scripting (XSS) vulnerabilityylefebvre · link library · CWE-79 | Medium6.1 | — | 0.3% | Jun 8, 2024 |
24Monitor | CVE-2024-13404No exploit | Link Library <= 7.7.2 - Reflected Cross-Site Scriptingylefebvre · link library · CWE-79 | Medium6.1 | — | 0.3% | Jan 21, 2025 |
21Monitor | CVE-2024-13441No exploit | Bilingual Linker <= 2.4 - Authenticated (Contributor+) Stored Cross-Site Scriptingylefebvre · bilingual linker · CWE-79 | Medium5.4 | — | 0.3% | Jan 25, 2025 |
21Monitor | CVE-2024-4281No exploit | Link Library <= 7.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via link-library Shortcodeylefebvre · link library · CWE-79 | Medium5.4 | — | 0.3% | May 8, 2024 |
21Monitor | CVE-2025-46237No exploit | WordPress Link Library plugin <= 7.8 - Cross Site Scripting (XSS) Vulnerabilityylefebvre · link library · CWE-79 | Medium5.4 | — | 0.2% | Apr 22, 2025 |
19Monitor | CVE-2022-4199No exploit | Link Library < 7.4.1 - Admin+ Stored XSSylefebvre · link library · CWE-79 | Medium4.8 | — | 0.5% | Jan 16, 2023 |
19Monitor | CVE-2023-24001No exploit | WordPress Modal Dialog Plugin <= 3.5.9 is vulnerable to Cross Site Scripting (XSS)ylefebvre · modal dialog · CWE-79 | Medium4.8 | — | 0.4% | Apr 6, 2023 |
- CVE-2024-2487535Monitor
WordPress Link Library Plugin <= 7.5.13 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%ylefebvre · link libraryFeb 12, 2024
- CVE-2021-2509330Monitor
Link Library < 7.2.8 - Unauthenticated Arbitrary Links Deletion
HighCVSS 7.5No exploitEPSS 1%ylefebvre · link libraryFeb 1, 2022
- CVE-2021-2509226Monitor
Link Library < 7.2.8 - Library Settings Reset via CSRF
MediumCVSS 6.5No exploitEPSS 0%ylefebvre · link libraryFeb 1, 2022
- CVE-2026-1819725Monitor
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripti
MediumCVSS 6.4No exploitEPSS 0%ylefebvre · link libraryJul 29, 2026
- CVE-2021-2509124Monitor
Link Library < 7.2.9 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 1%ylefebvre · link libraryFeb 1, 2022
- CVE-2024-2912324Monitor
WordPress Link Library plugin <= 7.6 - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%ylefebvre · link libraryMar 19, 2024
- CVE-2024-155924Monitor
Link Library <= 7.6 - Unauthenticated Stored Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%ylefebvre · link libraryFeb 20, 2024
- CVE-2024-232524Monitor
Link Library <= 7.6.6 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%ylefebvre · link libraryApr 9, 2024
- CVE-2023-3107124Monitor
WordPress Modal Dialog Plugin <= 3.5.14 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%ylefebvre · modal dialogAug 17, 2023
- CVE-2024-2487924Monitor
WordPress Link Library Plugin <= 7.5.13 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%ylefebvre · link libraryFeb 8, 2024
- CVE-2024-3871124Monitor
WordPress Link Library plugin <= 7.7.1 - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%ylefebvre · link libraryJul 20, 2024
- CVE-2024-3568724Monitor
WordPress Link Library plugin <= 7.6.3 - Reflected Cross-Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%ylefebvre · link libraryJun 8, 2024
- CVE-2024-1340424Monitor
Link Library <= 7.7.2 - Reflected Cross-Site Scripting
MediumCVSS 6.1No exploitEPSS 0%ylefebvre · link libraryJan 21, 2025
- CVE-2024-1344121Monitor
Bilingual Linker <= 2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%ylefebvre · bilingual linkerJan 25, 2025
- CVE-2024-428121Monitor
Link Library <= 7.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via link-library Shortcode
MediumCVSS 5.4No exploitEPSS 0%ylefebvre · link libraryMay 8, 2024
- CVE-2025-4623721Monitor
WordPress Link Library plugin <= 7.8 - Cross Site Scripting (XSS) Vulnerability
MediumCVSS 5.4No exploitEPSS 0%ylefebvre · link libraryApr 22, 2025
- CVE-2022-419919Monitor
Link Library < 7.4.1 - Admin+ Stored XSS
MediumCVSS 4.8No exploitEPSS 0%ylefebvre · link libraryJan 16, 2023
- CVE-2023-2400119Monitor
WordPress Modal Dialog Plugin <= 3.5.9 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%ylefebvre · modal dialogApr 6, 2023