Yooslider develops a slider/carousel plugin for web applications, with its vulnerability footprint concentrated in the core Yoo Slider product around web-application layer issues. The recurring exposure centers on input-validation weaknesses including cross-site scripting and cross-site request forgery, typical of client-side interface components exposed to untrusted content and user interaction; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yooslider over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25609MEDIUM Stored Cross-Site Scripting (XSS) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers with contributor or higher user role to inject the malicious code. | Mar 23, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-25608MEDIUM Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to trick authenticated users into unwanted slider duplicate or del | Mar 23, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-27847MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to import templates. | Apr 13, 2022 | 4.3 | 18 | NO | NO |
CVE-2022-27846MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to create or modify slider. | Apr 13, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yooslider.
Media articles that mention a CVE ID that affects a product developed by Yooslider — matched by CVE ID, not by vendor name.