Skip to content
Noroxi

yourls records

8 published records for vendor yourls.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
37.5%
Median publish → KEV
No record has entered KEV

All records

8 records
  • YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    yourls · yourlsAug 7, 2019

  • CVE-2021-3734
    35Monitor

    Improper Restriction of Rendered UI Layers or Frames in yourls/yourls

    HighCVSS 8.8No exploitEPSS 0%

    yourls · yourlsAug 26, 2021

  • CVE-2022-0088
    30Monitor

    Cross-Site Request Forgery (CSRF) in yourls/yourls

    HighCVSS 7.4Proof of conceptEPSS 2%

    yourls · yourlsApr 3, 2022

  • CVE-2021-3783
    24Monitor

    Cross-site Scripting (XSS) - Reflected in yourls/yourls

    MediumCVSS 6.1No exploitEPSS 1%

    yourls · yourlsSep 15, 2021

  • CVE-2021-3785
    21Monitor

    Cross-site Scripting (XSS) - Stored in yourls/yourls

    MediumCVSS 5.4No exploitEPSS 1%

    yourls · yourlsSep 15, 2021

  • Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10.

    MediumCVSS 5.4No exploitEPSS 1%

    yourls · yourlsOct 23, 2020

  • CVE-2011-3824
    20Monitor

    Your Own URL Shortener (YOURLS) 1.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which revea

    MediumCVSS 5.0No exploitEPSS 1%

    yourls · yourlsSep 23, 2011

  • CVE-2014-8488
    18Monitor

    Cross-site scripting (XSS) vulnerability in the administrator panel in Yourls 1.7 allows remote attackers to inject arbitrary web script or

    MediumCVSS 4.3No exploitEPSS 2%

    yourls · yourlsDec 9, 2014