Known Vulnerabilities for products from Squirrly

Listed below are 12 of the newest known vulnerabilities associated with the vendor "Squirrly".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2025-24654 json Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugin by ... Not Provided 2025-03-03 2026-04-01
CVE-2025-22783 json Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SEO Squirrly SEO Plugin... Not Provided 2025-03-27 2026-04-01
CVE-2024-6497 json The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter ... Not Provided 2024-07-20 2026-04-08
CVE-2024-3679 json The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u... Not Provided 2024-08-29 2026-04-08
CVE-2024-0597 json The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve... Not Provided 2024-02-05 2026-04-08
CVE-2024-0366 json The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versi... Not Provided 2024-02-05 2026-04-08
CVE-2024-0256 json The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Setting... Not Provided 2024-02-07 2026-04-08
CVE-2023-50854 json 7.2 - HIGH 2023-12-28 2024-01-05
CVE-2023-6806 json The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields in all... Not Provided 2024-02-29 2026-04-08
CVE-2022-45065 json Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Squirrly SEO Plugin by Squirrly SEO plugin <= 12.1.20 versions... 6.1 - MEDIUM 2023-05-08 2023-06-07
CVE-2022-38140 json Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress. 8.8 - HIGH 2022-11-28 2023-11-07
CVE-2021-25019 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 6.1 - MEDIUM 2022-03-21 2023-06-07