Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-0088 | Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3. Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3. NVD description · AI analysis pending | 7.4 | 2% | PoC |
| — | |
| CVE-2021-3783 +1 in the same advisory: …3785 | yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') NVD description · AI analysis pending | 6.1 group max | <1% |
| — | ||
| CVE-2021-3734 | yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2020-27388 | Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2019-14537 | YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass. YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass. NVD description · AI analysis pending | 9.8 | 6% | PoC ×2 |
| — |