Skip to content
Noroxi

Yoast records

17 published records for vendor yoast.

All records

17 records
  • The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.

    CriticalCVSS 9.8No exploitEPSS 3%

    yoast · yoast seoJul 9, 2019

  • WordPress Yoast SEO: Local Plugin <= 14.8 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    yoast · yoast local seoNov 18, 2023

  • CVE-2015-2292
    28Monitor

    Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x be

    MediumCVSS 6.5Proof of conceptEPSS 6%

    yoast · wordpress seoMar 17, 2015

  • A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0

    MediumCVSS 6.6No exploitEPSS 3%

    yoast · yoast seoNov 28, 2018

  • CVE-2015-2293
    27Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be

    MediumCVSS 6.8No exploitEPSS 2%

    yoast · wordpress seoMar 17, 2015

  • The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.

    MediumCVSS 6.4No exploitEPSS 0%

    yoast · yoast seoApr 28, 2021

  • Google Analytics Dashboard Plugin cross site scriting

    MediumCVSS 6.1No exploitEPSS 1%

    yoast · google analytics dashboardJun 24, 2022

  • WordPress Yoast SEO: Local Plugin <= 14.8 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 6.1No exploitEPSS 0%

    yoast · yoast seoAug 23, 2023

  • Yoast SEO 16.7-17.2 - Unauthenticated Full Path Disclosure

    MediumCVSS 5.3Proof of conceptEPSS 6%

    yoast · yoast seoFeb 28, 2022

  • Yoast SEO < 3.4.1 - Authenticated Stored Cross-Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 1%

    yoast · yoast seoApr 5, 2021

  • The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.

    MediumCVSS 5.4No exploitEPSS 0%

    yoast · yoast seoAug 13, 2021

  • WordPress Yoast SEO: Local Plugin <= 14.9 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 5.4No exploitEPSS 0%

    yoast · yoast seoMay 28, 2023

  • WordPress Yoast SEO Premium plugin <= 20.4 - Unauthenticated Zapier API Key Reset vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    yoast · yoast seoJun 11, 2024

  • Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin before 5.8.0 for WordPre

    MediumCVSS 4.8No exploitEPSS 1%

    yoast · wordpress seoNov 15, 2017

  • WordPress Yoast SEO Plugin <= 21.0 is vulnerable to Cross Site Scripting (XSS)

    MediumCVSS 4.8No exploitEPSS 0%

    yoast · yoast seoNov 30, 2023

  • CVE-2012-6692
    18Monitor

    Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remote

    MediumCVSS 4.3No exploitEPSS 3%

    yoast · wordpress seoJun 17, 2015

  • CVE-2014-9174
    18Monitor

    Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress

    MediumCVSS 4.3No exploitEPSS 2%

    yoast · google analyticsDec 2, 2014