Known Vulnerabilities for Yoast Seo by Yoast
Listed below are 9 of the newest known vulnerabilities associated with "Yoast Seo" by "Yoast".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-24591 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yasir129 Turn Yoast SEO... | Not Provided | 2026-01-23 | 2026-04-23 |
| CVE-2026-1217 json | The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... | Not Provided | 2026-03-18 | 2026-04-08 |
| CVE-2024-4984 json | The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ author meta in all... | Not Provided | 2024-05-16 | 2026-04-08 |
| CVE-2024-4041 json | The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and includ... | Not Provided | 2024-05-14 | 2026-04-08 |
| CVE-2023-40680 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 4.8 - MEDIUM | 2023-11-30 | 2023-12-05 |
| CVE-2023-32300 json | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions. | 6.1 - MEDIUM | 2023-08-23 | 2023-08-29 |
| CVE-2023-28785 json | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions. | 5.4 - MEDIUM | 2023-05-28 | 2023-06-01 |
| CVE-2021-36788 json | The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS. | 5.4 - MEDIUM | 2021-08-13 | 2021-08-20 |
| CVE-2021-31779 json | The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account. | 6.4 - MEDIUM | 2021-04-28 | 2021-05-07 |
| CVE-2021-25118 json | The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts v... | 5.3 - MEDIUM | 2022-02-28 | 2022-10-27 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Yoast | Yoast Seo | 9.8 | |||
| Application | Yoast | Yoast Seo | 9.7 | |||
| Application | Yoast | Yoast Seo | 9.7 | |||
| Application | Yoast | Yoast Seo | 9.7 | |||
| Application | Yoast | Yoast Seo | 9.7 | |||
| Application | Yoast | Yoast Seo | 9.7 | |||
| Application | Yoast | Yoast Seo | 9.7 | |||
| Application | Yoast | Yoast Seo | 9.6 | |||
| Application | Yoast | Yoast Seo | 9.6 | |||
| Application | Yoast | Yoast Seo | 9.6 | |||
| Application | Yoast | Yoast Seo | 9.6 | |||
| Application | Yoast | Yoast Seo | 9.6 | |||
| Application | Yoast | Yoast Seo | 9.6 | |||
| Application | Yoast | Yoast Seo | 9.5 | |||
| Application | Yoast | Yoast Seo | 9.5 | |||
| Application | Yoast | Yoast Seo | 9.5 | |||
| Application | Yoast | Yoast Seo | 9.5 | |||
| Application | Yoast | Yoast Seo | 9.5 | |||
| Application | Yoast | Yoast Seo | 9.5 | |||
| Application | Yoast | Yoast Seo | 9.4 |