Yoast kayıtları
yoast üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %41,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
- CWE-862 Missing Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-13478İstismar yok | The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.yoast · yoast seo · CWE-79 | Kritik9,8 | — | %3,3 | 9 Tem 2019 |
35İzleyin | CVE-2023-28780İstismar yok | WordPress Yoast SEO: Local Plugin <= 14.8 is vulnerable to Cross Site Request Forgery (CSRF)yoast · yoast local seo · CWE-352 | Yüksek8,8 | — | %0,4 | 18 Kas 2023 |
28İzleyin | CVE-2015-2292Kavram kanıtı | Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x beyoast · wordpress seo · CWE-89 | Orta6,5 | — | %5,8 | 17 Mar 2015 |
27İzleyin | CVE-2018-19370İstismar yok | A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 yoast · yoast seo · CWE-362 | Orta6,6 | — | %3,2 | 28 Kas 2018 |
27İzleyin | CVE-2015-2293İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin beyoast · wordpress seo · CWE-352 | Orta6,8 | — | %1,5 | 17 Mar 2015 |
25İzleyin | CVE-2021-31779İstismar yok | The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.yoast · yoast seo · CWE-918 | Orta6,4 | — | %0,5 | 28 Nis 2021 |
24İzleyin | CVE-2017-20092İstismar yok | Google Analytics Dashboard Plugin cross site scritingyoast · google analytics dashboard · CWE-80 | Orta6,1 | — | %0,6 | 24 Haz 2022 |
24İzleyin | CVE-2023-32300İstismar yok | WordPress Yoast SEO: Local Plugin <= 14.8 is vulnerable to Cross Site Scripting (XSS)yoast · yoast seo · CWE-79 | Orta6,1 | — | %0,4 | 23 Ağu 2023 |
23İzleyin | CVE-2021-25118Kavram kanıtı | Yoast SEO 16.7-17.2 - Unauthenticated Full Path Disclosureyoast · yoast seo · CWE-200 | Orta5,3 | — | %5,6 | 28 Şub 2022 |
21İzleyin | CVE-2021-24153İstismar yok | Yoast SEO < 3.4.1 - Authenticated Stored Cross-Site Scripting (XSS)yoast · yoast seo · CWE-79 | Orta5,4 | — | %1,1 | 5 Nis 2021 |
21İzleyin | CVE-2021-36788İstismar yok | The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.yoast · yoast seo · CWE-79 | Orta5,4 | — | %0,5 | 13 Ağu 2021 |
21İzleyin | CVE-2023-28785İstismar yok | WordPress Yoast SEO: Local Plugin <= 14.9 is vulnerable to Cross Site Scripting (XSS)yoast · yoast seo · CWE-79 | Orta5,4 | — | %0,4 | 28 May 2023 |
21İzleyin | CVE-2023-28775İstismar yok | WordPress Yoast SEO Premium plugin <= 20.4 - Unauthenticated Zapier API Key Reset vulnerabilityyoast · yoast seo · CWE-862 | Orta5,3 | — | %0,4 | 11 Haz 2024 |
19İzleyin | CVE-2017-16842İstismar yok | Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin before 5.8.0 for WordPreyoast · wordpress seo · CWE-79 | Orta4,8 | — | %1,3 | 15 Kas 2017 |
19İzleyin | CVE-2023-40680İstismar yok | WordPress Yoast SEO Plugin <= 21.0 is vulnerable to Cross Site Scripting (XSS)yoast · yoast seo · CWE-79 | Orta4,8 | — | %0,4 | 30 Kas 2023 |
18İzleyin | CVE-2012-6692İstismar yok | Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remoteyoast · wordpress seo · CWE-79 | Orta4,3 | — | %3,2 | 17 Haz 2015 |
18İzleyin | CVE-2014-9174İstismar yok | Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPressyoast · google analytics · CWE-79 | Orta4,3 | — | %2,0 | 2 Ara 2014 |
- CVE-2019-1347840Planlayın
The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.
KritikCVSS 9,8İstismar yokEPSS %3yoast · yoast seo9 Tem 2019
- CVE-2023-2878035İzleyin
WordPress Yoast SEO: Local Plugin <= 14.8 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0yoast · yoast local seo18 Kas 2023
- CVE-2015-229228İzleyin
Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x be
OrtaCVSS 6,5Kavram kanıtıEPSS %6yoast · wordpress seo17 Mar 2015
- CVE-2018-1937027İzleyin
A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0
OrtaCVSS 6,6İstismar yokEPSS %3yoast · yoast seo28 Kas 2018
- CVE-2015-229327İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be
OrtaCVSS 6,8İstismar yokEPSS %2yoast · wordpress seo17 Mar 2015
- CVE-2021-3177925İzleyin
The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.
OrtaCVSS 6,4İstismar yokEPSS %0yoast · yoast seo28 Nis 2021
- CVE-2017-2009224İzleyin
Google Analytics Dashboard Plugin cross site scriting
OrtaCVSS 6,1İstismar yokEPSS %1yoast · google analytics dashboard24 Haz 2022
- CVE-2023-3230024İzleyin
WordPress Yoast SEO: Local Plugin <= 14.8 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %0yoast · yoast seo23 Ağu 2023
- CVE-2021-2511823İzleyin
Yoast SEO 16.7-17.2 - Unauthenticated Full Path Disclosure
OrtaCVSS 5,3Kavram kanıtıEPSS %6yoast · yoast seo28 Şub 2022
- CVE-2021-2415321İzleyin
Yoast SEO < 3.4.1 - Authenticated Stored Cross-Site Scripting (XSS)
OrtaCVSS 5,4İstismar yokEPSS %1yoast · yoast seo5 Nis 2021
- CVE-2021-3678821İzleyin
The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.
OrtaCVSS 5,4İstismar yokEPSS %0yoast · yoast seo13 Ağu 2021
- CVE-2023-2878521İzleyin
WordPress Yoast SEO: Local Plugin <= 14.9 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 5,4İstismar yokEPSS %0yoast · yoast seo28 May 2023
- CVE-2023-2877521İzleyin
WordPress Yoast SEO Premium plugin <= 20.4 - Unauthenticated Zapier API Key Reset vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0yoast · yoast seo11 Haz 2024
- CVE-2017-1684219İzleyin
Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin before 5.8.0 for WordPre
OrtaCVSS 4,8İstismar yokEPSS %1yoast · wordpress seo15 Kas 2017
- CVE-2023-4068019İzleyin
WordPress Yoast SEO Plugin <= 21.0 is vulnerable to Cross Site Scripting (XSS)
OrtaCVSS 4,8İstismar yokEPSS %0yoast · yoast seo30 Kas 2023
- CVE-2012-669218İzleyin
Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remote
OrtaCVSS 4,3İstismar yokEPSS %3yoast · wordpress seo17 Haz 2015
- CVE-2014-917418İzleyin
Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress
OrtaCVSS 4,3İstismar yokEPSS %2yoast · google analytics2 Ara 2014