Yoast records
17 published records for vendor yoast.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 41.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
- CWE-862 Missing Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-13478No exploit | The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.yoast · yoast seo · CWE-79 | Critical9.8 | — | 3.3% | Jul 9, 2019 |
35Monitor | CVE-2023-28780No exploit | WordPress Yoast SEO: Local Plugin <= 14.8 is vulnerable to Cross Site Request Forgery (CSRF)yoast · yoast local seo · CWE-352 | High8.8 | — | 0.4% | Nov 18, 2023 |
28Monitor | CVE-2015-2292Proof of concept | Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x beyoast · wordpress seo · CWE-89 | Medium6.5 | — | 5.8% | Mar 17, 2015 |
27Monitor | CVE-2018-19370No exploit | A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 yoast · yoast seo · CWE-362 | Medium6.6 | — | 3.2% | Nov 28, 2018 |
27Monitor | CVE-2015-2293No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin beyoast · wordpress seo · CWE-352 | Medium6.8 | — | 1.5% | Mar 17, 2015 |
25Monitor | CVE-2021-31779No exploit | The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.yoast · yoast seo · CWE-918 | Medium6.4 | — | 0.5% | Apr 28, 2021 |
24Monitor | CVE-2017-20092No exploit | Google Analytics Dashboard Plugin cross site scritingyoast · google analytics dashboard · CWE-80 | Medium6.1 | — | 0.6% | Jun 24, 2022 |
24Monitor | CVE-2023-32300No exploit | WordPress Yoast SEO: Local Plugin <= 14.8 is vulnerable to Cross Site Scripting (XSS)yoast · yoast seo · CWE-79 | Medium6.1 | — | 0.4% | Aug 23, 2023 |
23Monitor | CVE-2021-25118Proof of concept | Yoast SEO 16.7-17.2 - Unauthenticated Full Path Disclosureyoast · yoast seo · CWE-200 | Medium5.3 | — | 5.6% | Feb 28, 2022 |
21Monitor | CVE-2021-24153No exploit | Yoast SEO < 3.4.1 - Authenticated Stored Cross-Site Scripting (XSS)yoast · yoast seo · CWE-79 | Medium5.4 | — | 1.1% | Apr 5, 2021 |
21Monitor | CVE-2021-36788No exploit | The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.yoast · yoast seo · CWE-79 | Medium5.4 | — | 0.5% | Aug 13, 2021 |
21Monitor | CVE-2023-28785No exploit | WordPress Yoast SEO: Local Plugin <= 14.9 is vulnerable to Cross Site Scripting (XSS)yoast · yoast seo · CWE-79 | Medium5.4 | — | 0.4% | May 28, 2023 |
21Monitor | CVE-2023-28775No exploit | WordPress Yoast SEO Premium plugin <= 20.4 - Unauthenticated Zapier API Key Reset vulnerabilityyoast · yoast seo · CWE-862 | Medium5.3 | — | 0.4% | Jun 11, 2024 |
19Monitor | CVE-2017-16842No exploit | Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin before 5.8.0 for WordPreyoast · wordpress seo · CWE-79 | Medium4.8 | — | 1.3% | Nov 15, 2017 |
19Monitor | CVE-2023-40680No exploit | WordPress Yoast SEO Plugin <= 21.0 is vulnerable to Cross Site Scripting (XSS)yoast · yoast seo · CWE-79 | Medium4.8 | — | 0.4% | Nov 30, 2023 |
18Monitor | CVE-2012-6692No exploit | Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remoteyoast · wordpress seo · CWE-79 | Medium4.3 | — | 3.2% | Jun 17, 2015 |
18Monitor | CVE-2014-9174No exploit | Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPressyoast · google analytics · CWE-79 | Medium4.3 | — | 2.0% | Dec 2, 2014 |
- CVE-2019-1347840Plan
The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.
CriticalCVSS 9.8No exploitEPSS 3%yoast · yoast seoJul 9, 2019
- CVE-2023-2878035Monitor
WordPress Yoast SEO: Local Plugin <= 14.8 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%yoast · yoast local seoNov 18, 2023
- CVE-2015-229228Monitor
Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x be
MediumCVSS 6.5Proof of conceptEPSS 6%yoast · wordpress seoMar 17, 2015
- CVE-2018-1937027Monitor
A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0
MediumCVSS 6.6No exploitEPSS 3%yoast · yoast seoNov 28, 2018
- CVE-2015-229327Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be
MediumCVSS 6.8No exploitEPSS 2%yoast · wordpress seoMar 17, 2015
- CVE-2021-3177925Monitor
The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.
MediumCVSS 6.4No exploitEPSS 0%yoast · yoast seoApr 28, 2021
- CVE-2017-2009224Monitor
Google Analytics Dashboard Plugin cross site scriting
MediumCVSS 6.1No exploitEPSS 1%yoast · google analytics dashboardJun 24, 2022
- CVE-2023-3230024Monitor
WordPress Yoast SEO: Local Plugin <= 14.8 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%yoast · yoast seoAug 23, 2023
- CVE-2021-2511823Monitor
Yoast SEO 16.7-17.2 - Unauthenticated Full Path Disclosure
MediumCVSS 5.3Proof of conceptEPSS 6%yoast · yoast seoFeb 28, 2022
- CVE-2021-2415321Monitor
Yoast SEO < 3.4.1 - Authenticated Stored Cross-Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 1%yoast · yoast seoApr 5, 2021
- CVE-2021-3678821Monitor
The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.
MediumCVSS 5.4No exploitEPSS 0%yoast · yoast seoAug 13, 2021
- CVE-2023-2878521Monitor
WordPress Yoast SEO: Local Plugin <= 14.9 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%yoast · yoast seoMay 28, 2023
- CVE-2023-2877521Monitor
WordPress Yoast SEO Premium plugin <= 20.4 - Unauthenticated Zapier API Key Reset vulnerability
MediumCVSS 5.3No exploitEPSS 0%yoast · yoast seoJun 11, 2024
- CVE-2017-1684219Monitor
Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin before 5.8.0 for WordPre
MediumCVSS 4.8No exploitEPSS 1%yoast · wordpress seoNov 15, 2017
- CVE-2023-4068019Monitor
WordPress Yoast SEO Plugin <= 21.0 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%yoast · yoast seoNov 30, 2023
- CVE-2012-669218Monitor
Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remote
MediumCVSS 4.3No exploitEPSS 3%yoast · wordpress seoJun 17, 2015
- CVE-2014-917418Monitor
Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress
MediumCVSS 4.3No exploitEPSS 2%yoast · google analyticsDec 2, 2014