Yoast develops a focused suite of search-engine optimization and analytics plugins for WordPress, which are broadly deployed across web publishers and e-commerce sites. The vendor's vulnerability footprint centers on web application input-handling and state-management weaknesses, particularly cross-site scripting, cross-site request forgery, and race conditions that arise in plugin contexts where user input and administrative actions intersect, and these disclosures show a tendency toward public exploit availability. Defenders should treat updates to Yoast plugins as routine maintenance priorities given their prevalence in WordPress deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yoast over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25118MEDIUM The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an a | Feb 28, 2022 | 5.3 | 34 | NO | YES |
CVE-2019-13478CRITICAL The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions. | Jul 9, 2019 | 9.8 | 31 | NO | NO |
CVE-2015-2292MEDIUM Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for W | Mar 17, 2015 | 6.5 | 28 | NO | YES |
CVE-2023-28780HIGH Cross-Site Request Forgery (CSRF) vulnerability in Yoast Yoast Local Premium.This issue affects Yoast Local Premium: from n/a through 14.8. | Nov 18, 2023 | 8.8 | 25 | NO | NO |
CVE-2018-19370MEDIUM A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) plugin before 9.2.0 for WordPress allows an SEO Manager to p | Nov 28, 2018 | 6.6 | 23 | NO | NO |
CVE-2017-20092MEDIUM A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads t | Jun 24, 2022 | 6.1 | 21 | NO | NO |
CVE-2021-31779MEDIUM The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account. | Apr 28, 2021 | 6.4 | 21 | NO | NO |
CVE-2021-36788MEDIUM The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS. | Aug 13, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-24153MEDIUM A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis | Apr 5, 2021 | 5.4 | 19 | NO | NO |
CVE-2023-32300MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions. | Aug 23, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yoast.
Media articles that mention a CVE ID that affects a product developed by Yoast — matched by CVE ID, not by vendor name.