Yoast
Yoast SEO: vulnerabilidades y CVE
Yoast SEO tiene 16 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-15425 | Media (6.4) | 0.35% | — | 25 jul 2026 | The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up to, and including, 28.0 due to… |
| CVE-2025-14481 | Media (4.3) | 0.29% | — | 27 may 2026 | The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and including, 26.5. This is due to insufficient authorization checks in the Meta Search REST API endpoint… |
| CVE-2026-3427 | Media (6.4) | 0.33% | — | 22 mar 2026 | The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `jsonText` block attribute in all versions up to, and including, 27.1.1… |
| CVE-2026-1293 | Media (6.4) | 0.20% | — | 6 feb 2026 | The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `yoast-schema` block attribute in all versions up to, and including,… |
| CVE-2023-28775 | Media (5.3) | 0.35% | — | 11 jun 2024 | Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4. |
| CVE-2024-4984 | Media (6.4) | 0.63% | — | 16 may 2024 | The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ author meta in all versions up to, and including, 22.6 due to insufficient input sanitization and output escaping.… |
| CVE-2024-4041 | Media (6.1) | 0.83% | — | 14 may 2024 | The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 22.5 due to insufficient input sanitization and output escaping. This makes it possible… |
| CVE-2023-40680 | Media (4.8) | 0.43% | — | 30 nov 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team Yoast Yoast SEO allows Stored XSS.This issue affects Yoast SEO: from n/a through 21.0. |
| CVE-2023-32300 | Media (6.1) | 0.38% | — | 23 ago 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions. |
| CVE-2023-28785 | Media (5.4) | 0.37% | — | 28 may 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.9 versions. |
| CVE-2021-25118 | Media (5.3) | 5.6% | — | 28 feb 2022 | The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities… |
| CVE-2021-36788 | Media (5.4) | 0.47% | — | 13 ago 2021 | The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS. |
| CVE-2021-31779 | Media (6.4) | 0.47% | — | 28 abr 2021 | The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account. |
| CVE-2021-24153 | Media (5.4) | 1.1% | — | 5 abr 2021 | A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as… |
| CVE-2019-13478 | Crítica (9.8) | 3.3% | — | 9 jul 2019 | The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions. |
| CVE-2018-19370 | Media (6.6) | 3.2% | — | 28 nov 2018 | A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to perform command execution on the… |