Vulnerabilities (CVE)

Filtered by vendor Yoast Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-40680 1 Yoast 1 Yoast Seo 2023-12-05 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Yoast Yoast SEO allows Stored XSS.This issue affects Yoast SEO: from n/a through 21.0.
CVE-2023-32300 1 Yoast 1 Yoast Seo 2023-08-29 N/A 6.1 MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions.
CVE-2017-20092 1 Yoast 1 Google Analytics Dashboard 2022-06-30 4.3 MEDIUM 6.1 MEDIUM
A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.
CVE-2021-36788 1 Yoast 1 Yoast Seo 2021-08-20 3.5 LOW 5.4 MEDIUM
The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.
CVE-2021-31779 1 Yoast 1 Yoast Seo 2021-05-07 5.5 MEDIUM 6.4 MEDIUM
The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.
CVE-2021-24153 1 Yoast 1 Yoast Seo 2021-04-09 3.5 LOW 5.4 MEDIUM
A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.
CVE-2018-19370 1 Yoast 1 Yoast Seo 2019-01-31 6.0 MEDIUM 6.6 MEDIUM
A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.
CVE-2017-16842 1 Yoast 1 Wordpress Seo 2017-12-03 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin before 5.8.0 for WordPress allows remote attackers to inject arbitrary web script or HTML.