VYPR

Yoast SEO Premium

by WordPress

CVEs (4)

  • CVE-2026-10821MedSep 2, 2026
    risk 0.43cvss 6.6epss 0.01

    The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, and the redirect-creation endpoint is reachable by users with…

  • CVE-2025-11241MedOct 3, 2025
    risk 0.42cvss 6.4epss 0.00

    The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to a flawed regex used to remove an attribute in post content, which can be abused to inject arbitrary HTML attributes, including JavaScript event handlers. This…

  • CVE-2026-40722MedJun 17, 2026
    risk 0.36cvss 5.5epss 0.00

    Missing Authorization vulnerability in Yoast BV Yoast SEO Premium allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Yoast SEO Premium: from n/a through 26.6.

  • CVE-2023-28775MedJun 11, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Yoast Yoast SEO Premium.This issue affects Yoast SEO Premium: from n/a through 20.4.