Ylefebvre maintains a focused portfolio of development and web-integration tools—including a link library, modal dialog components, and a bilingual linker—that occupy a niche but prominent role in specialized development workflows. Its vulnerability disclosures recur around application-layer input handling and access control, with a durable pattern of cross-site scripting, cross-site request forgery, and missing authorization weaknesses that are characteristic of web-facing and component-based software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ylefebvre over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24875HIGH Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13. | Feb 12, 2024 | 8.8 | 24 | NO | NO |
CVE-2021-25093HIGH The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted requ | Feb 1, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-25092MEDIUM The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a | Feb 1, 2022 | 6.5 | 22 | NO | NO |
CVE-2023-31071MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yannick Lefebvre Modal Dialog plugin <= 3.5.14 versions. | Aug 17, 2023 | 6.1 | 21 | NO | NO |
CVE-2021-25091MEDIUM The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site | Feb 1, 2022 | 6.1 | 21 | NO | NO |
CVE-2024-35687MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Reflected XSS.This is | Jun 8, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-24879MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Lib | Feb 8, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-24001MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Yannick Lefebvre Modal Dialog plugin <= 3.5.9 versions. | Apr 6, 2023 | 4.8 | 19 | NO | NO |
CVE-2022-4199MEDIUM The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site | Jan 16, 2023 | 4.8 | 19 | NO | NO |
CVE-2025-46237MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Stored XSS.This issue affect | Apr 22, 2025 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ylefebvre.
Media articles that mention a CVE ID that affects a product developed by Ylefebvre — matched by CVE ID, not by vendor name.