Browse all 10 CVE security advisories affecting yoast. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Yoast is a WordPress plugin focused on SEO optimization and content management. Historically, vulnerabilities have commonly included stored cross-site scripting (XSS), arbitrary file uploads, and privilege escalation flaws, with several instances allowing remote code execution. The plugin's extensive user base has made it a frequent target for exploitation. In 2020, a critical RCE vulnerability (CVE-2020-14040) affected versions prior to 14.1.1, enabling attackers to execute arbitrary code through crafted requests. While Yoast has addressed these issues through patches, its complex functionality and integration with WordPress core continue to present potential attack surfaces, requiring regular updates and input sanitization to mitigate risks.
This page lists every published CVE security advisory associated with yoast. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.