Known Vulnerabilities for Yoast Seo by Yoast
Listed below are 9 of the newest known vulnerabilities associated with "Yoast Seo" by "Yoast".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-57764 json | Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions. | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-53740 json | Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish no... | Not Provided | 2026-06-10 | 2026-06-11 |
| CVE-2026-53739 json | Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice han... | Not Provided | 2026-06-10 | 2026-06-11 |
| CVE-2026-40722 json | Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Sec... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-15425 json | The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Sit... | Not Provided | 2026-07-25 | 2026-07-27 |
| CVE-2025-14481 json | The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and including, 2... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2023-40680 json | Not Provided | 2023-11-30 | 2026-04-28 | |
| CVE-2023-32300 json | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions. | 6.1 - MEDIUM | 2023-08-23 | 2023-08-29 |
| CVE-2023-28785 json | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions. | 5.4 - MEDIUM | 2023-05-28 | 2023-06-01 |
| CVE-2021-36788 json | The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS. | 5.4 - MEDIUM | 2021-08-13 | 2021-08-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Yoast | Yoast Seo | 9.8 | |||
| Application | Yoast | Yoast Seo | 9.7 | |||
| Application | Yoast | Yoast Seo | 9.7 | |||
| Application | Yoast | Yoast Seo | 9.7 | |||
| Application | Yoast | Yoast Seo | 9.7 | |||
| Application | Yoast | Yoast Seo | 9.7 | |||
| Application | Yoast | Yoast Seo | 9.7 | |||
| Application | Yoast | Yoast Seo | 9.6 | |||
| Application | Yoast | Yoast Seo | 9.6 | |||
| Application | Yoast | Yoast Seo | 9.6 | |||
| Application | Yoast | Yoast Seo | 9.6 | |||
| Application | Yoast | Yoast Seo | 9.6 | |||
| Application | Yoast | Yoast Seo | 9.6 | |||
| Application | Yoast | Yoast Seo | 9.5 | |||
| Application | Yoast | Yoast Seo | 9.5 | |||
| Application | Yoast | Yoast Seo | 9.5 | |||
| Application | Yoast | Yoast Seo | 9.5 | |||
| Application | Yoast | Yoast Seo | 9.5 | |||
| Application | Yoast | Yoast Seo | 9.5 | |||
| Application | Yoast | Yoast Seo | 9.4 |