Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yourls

First CVE: Sep 24, 2011Active for: 15 yearsTotal CVEs: 8

Yourls is a self-hosted URL shortening application that, despite a narrow product scope, occupies a prominent position among lightweight web-based utilities and recurs across diverse deployment contexts. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure centers on web application fundamentals including cross-site scripting, cross-site request forgery, type confusion, and information disclosure, reflecting the complexity of input handling and session management in URL-processing logic. Defenders should treat Yourls instances, particularly internet-facing or multi-user deployments, as requiring prompt patching; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Yourls over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 24, 2011
14 years ago
Most Recent CVE
Apr 3, 2022
1,573 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-14537CRITICAL
YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
Aug 7, 20199.831NONO
CVE-2022-0088HIGH
Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.
Apr 3, 20227.428NOYES
CVE-2021-3734HIGH
yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames
Aug 26, 20218.827NONO
CVE-2020-27388MEDIUM
Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious p
Oct 23, 20205.422NONO
CVE-2021-3783MEDIUM
yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Sep 15, 20216.121NONO
CVE-2021-3785MEDIUM
yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Sep 15, 20215.420NONO
CVE-2014-8488MEDIUM
Cross-site scripting (XSS) vulnerability in the administrator panel in Yourls 1.7 allows remote attackers to inject arbitrary web script or HTML via a URL that is processed by the
Dec 10, 20144.318NONO
CVE-2011-3824MEDIUM
Your Own URL Shortener (YOURLS) 1.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error mes
Sep 24, 20115.018NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
63%
25%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (75.0%)
Unknown2 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High0 (0.0%)
Unknown2 (25.0%)
User Interaction
None1 (12.5%)
Unknown2 (25.0%)
Required5 (62.5%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None4 (50.0%)
Unknown2 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yourls.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yourls — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yourls's Products

View all 2 CNAs →

Top CWEs