YoastCVEs & Vulnerabilities

17 CVEs affecting Yoast products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

wordpress seo 24yoast seo 11google analytics 3google analytics dashboard 1yoast local seo 1
CVE-2023-28775MEDIUM

Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.

11 Jun 2024
5.3
CVSS
CVE-2023-40680MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Yoast Yoast SEO allows Stored XSS.This issue affects Yoast SEO: from n/a through 21.0.

30 Nov 2023
4.8
CVSS
CVE-2023-28780HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Yoast Yoast Local Premium.This issue affects Yoast Local Premium: from n/a through 14.8.

19 Nov 2023
8.8
CVSS
CVE-2023-32300MEDIUM

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions.

23 Aug 2023
6.1
CVSS
CVE-2023-28785MEDIUM

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions.

28 May 2023
5.4
CVSS
CVE-2017-20092MEDIUM

A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.

24 Jun 2022
6.1
CVSS
CVE-2021-25118MEDIUM

The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities.

28 Feb 2022
5.3
CVSS
CVE-2021-36788MEDIUM

The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.

13 Aug 2021
5.4
CVSS
CVE-2021-31779MEDIUM

The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.

28 Apr 2021
6.4
CVSS
CVE-2021-24153MEDIUM

A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.

5 Apr 2021
5.4
CVSS
CVE-2019-13478CRITICAL

The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.

10 Jul 2019
9.8
CVSS
CVE-2018-19370MEDIUM

A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the Operating System via a ZIP import.

29 Nov 2018
6.6
CVSS
CVE-2017-16842MEDIUM

Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin before 5.8.0 for WordPress allows remote attackers to inject arbitrary web script or HTML.

16 Nov 2017
4.8
CVSS
CVE-2012-6692MEDIUM

Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_title parameter to wp-admin/post-new.php, which is not properly handled in the snippet preview functionality.

17 Jun 2015
4.3
CVSS
CVE-2015-2293MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote attackers to hijack the authentication of certain users for requests that conduct SQL injection attacks via the (1) order_by or (2) order parameter in the wpseo_bulk-editor page.

17 Mar 2015
6.8
CVSS
CVE-2015-2292MEDIUMpoc

Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) order_by or (2) order parameter in the wpseo_bulk-editor page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

17 Mar 2015
6.5
CVSS
CVE-2014-9174MEDIUM

Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Manually enter your UA code" (manual_ua_code_field) field in the General Settings.

2 Dec 2014
4.3
CVSS
← PrevPage 1 / 1Next →
Yoast CVEs & Vulnerabilities — 17 Tracked