Skip to main content

Vendor archive

aioseo CVEs

Beta · best-effort

10 CVEs tagged to vendor aioseo0 Critical, 2 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2025-2892

Published May 19, 2025

The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post Meta Description a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3368

Published May 20, 2024

The All in One SEO WordPress plugin before 4.6.1.1 does not validate and escape some of its Post fields before outputting them back, which could allow users with the contributor…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3554

Published May 2, 2024

The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0586

Published Feb 24, 2023

The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-0585

Published Feb 24, 2023

The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input…

CVSS 4.4 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2022-42494

Published Nov 8, 2022

Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.

CVSS 3.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-38093

Published Sep 9, 2022

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25037

Published Jan 17, 2022

The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25036

Published Jan 17, 2022

The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may gra…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24307

Published May 24, 2021

The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the ti…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1