| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-3427 | Yoast SEO <= 27.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'jsonText' Block Attribute | yoast | Yoast SEO – Advanced SEO with real-time guidance and built-in AI | Medium | 6.4 | 2026-03-22 03:26:35 | Deep Dive |
| CVE-2026-1293 | Yoast SEO <= 26.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'yoast-schema' Block Attribute | yoast | Yoast SEO – Advanced SEO with real-time guidance and built-in AI | Medium | 6.4 | 2026-02-06 11:21:31 | Deep Dive |
| CVE-2026-24591 | WordPress Turn Yoast SEO FAQ Block to Accordion plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerability | yasir129 | Turn Yoast SEO FAQ Block to Accordion | Medium | 6.5 | 2026-01-23 14:29:01 | Deep Dive |
| CVE-2025-11241 | Yoast SEO Premium 25.7-25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting | - | Yoast SEO Premium | Medium | 6.4 | 2025-10-03 01:56:44 | Deep Dive |
| CVE-2023-28775 | WordPress Yoast SEO Premium plugin <= 20.4 - Unauthenticated Zapier API Key Reset vulnerability | Yoast | Yoast SEO Premium | Medium | 5.3 | 2024-06-11 09:16:19 | Deep Dive |
| CVE-2024-4984 | Yoast SEO <= 22.6 - Authenticated (Contributor+) Stored Cross-Site Scripting | yoast | Yoast SEO – Advanced SEO with real-time guidance and built-in AI | Medium | 6.4 | 2024-05-16 02:02:36 | Deep Dive |
| CVE-2024-4041 | Yoast SEO <= 22.5 - Reflected Cross-Site Scripting | yoast | Yoast SEO – Advanced SEO with real-time guidance and built-in AI | Medium | 6.1 | 2024-05-09 20:03:26 | Deep Dive |
| CVE-2023-40680 | WordPress Yoast SEO Plugin <= 21.0 is vulnerable to Cross Site Scripting (XSS) | Team Yoast | Yoast SEO | Medium | 5.9 | 2023-11-30 12:21:55 | Deep Dive |
| CVE-2023-32300 | WordPress Yoast SEO: Local Plugin <= 14.8 is vulnerable to Cross Site Scripting (XSS) | Yoast | Yoast SEO: Local | High | 7.1 | 2023-08-23 14:12:37 | Deep Dive |
| CVE-2023-28785 | WordPress Yoast SEO: Local Plugin <= 14.9 is vulnerable to Cross Site Scripting (XSS) | Yoast | Yoast SEO: Local | Medium | 6.5 | 2023-05-28 18:47:18 | Deep Dive |
| CVE-2021-25118 | Yoast SEO 16.7-17.2 - Unauthenticated Full Path Disclosure | Unknown | Yoast SEO | 中危 | - | 2022-02-28 09:06:38 | Deep Dive |
| CVE-2021-24153 | Yoast SEO < 3.4.1 - Authenticated Stored Cross-Site Scripting (XSS) | Unknown | Yoast SEO | 中危 | - | 2021-04-05 18:27:42 | Deep Dive |