Yourls is a self-hosted URL shortening application that, despite a narrow product scope, occupies a prominent position among lightweight web-based utilities and recurs across diverse deployment contexts. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure centers on web application fundamentals including cross-site scripting, cross-site request forgery, type confusion, and information disclosure, reflecting the complexity of input handling and session management in URL-processing logic. Defenders should treat Yourls instances, particularly internet-facing or multi-user deployments, as requiring prompt patching; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yourls over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14537CRITICAL YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass. | Aug 7, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-0088HIGH Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3. | Apr 3, 2022 | 7.4 | 28 | NO | YES |
CVE-2021-3734HIGH yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames | Aug 26, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-27388MEDIUM Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious p | Oct 23, 2020 | 5.4 | 22 | NO | NO |
CVE-2021-3783MEDIUM yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Sep 15, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-3785MEDIUM yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Sep 15, 2021 | 5.4 | 20 | NO | NO |
CVE-2014-8488MEDIUM Cross-site scripting (XSS) vulnerability in the administrator panel in Yourls 1.7 allows remote attackers to inject arbitrary web script or HTML via a URL that is processed by the | Dec 10, 2014 | 4.3 | 18 | NO | NO |
CVE-2011-3824MEDIUM Your Own URL Shortener (YOURLS) 1.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error mes | Sep 24, 2011 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yourls.
Media articles that mention a CVE ID that affects a product developed by Yourls — matched by CVE ID, not by vendor name.