Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ylefebvre

First CVE: Feb 1, 2022Active for: 4 yearsTotal CVEs: 17
8.9
VTI Score
Low

Ylefebvre maintains a focused portfolio of development and web-integration tools—including a link library, modal dialog components, and a bilingual linker—that occupy a niche but prominent role in specialized development workflows. Its vulnerability disclosures recur around application-layer input handling and access control, with a durable pattern of cross-site scripting, cross-site request forgery, and missing authorization weaknesses that are characteristic of web-facing and component-based software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ylefebvre over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2022
4 years ago
Most Recent CVE
Apr 22, 2025
458 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-24875HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.
Feb 12, 20248.824NONO
CVE-2021-25093HIGH
The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted requ
Feb 1, 20227.524NONO
CVE-2021-25092MEDIUM
The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a
Feb 1, 20226.522NONO
CVE-2023-31071MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yannick Lefebvre Modal Dialog plugin <= 3.5.14 versions.
Aug 17, 20236.121NONO
CVE-2021-25091MEDIUM
The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site
Feb 1, 20226.121NONO
CVE-2024-35687MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Reflected XSS.This is
Jun 8, 20246.119NONO
CVE-2024-24879MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Lib
Feb 8, 20246.119NONO
CVE-2023-24001MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Yannick Lefebvre Modal Dialog plugin <= 3.5.9 versions.
Apr 6, 20234.819NONO
CVE-2022-4199MEDIUM
The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site
Jan 16, 20234.819NONO
CVE-2025-46237MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Stored XSS.This issue affect
Apr 22, 20255.418NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
88%
12%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (5.9%)
Unknown0 (0.0%)
Required16 (94.1%)
Privileges Required
Low3 (17.6%)
High2 (11.8%)
None12 (70.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ylefebvre.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ylefebvre — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ylefebvre's Products

View all 3 CNAs →

Top CWEs