Aggregates CVE and security vulnerability intelligence across all yasglobal-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Disclosed issues often relate to vendor risk csrf and vendor risk cross-site scripting; exposure may include vendor impact session compromise in vendor surface production workloads and vendor surface software deployment contexts.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-47773 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YAS Global Team Permalinks Customizer plugin <= 2.8.2 versions. | [email protected] | 7.1 | 0.08% | 2023-11-22 | 2024-11-21 |
| CVE-2023-27433 | Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative allows Cross Site Request Forgery.This issue affects Make Paths Relative: from n/a through 1.3.0. | [email protected] | 5.4 | 0.09% | 2023-10-04 | 2024-11-21 |
| CVE-2023-27435 | Cross-Site Request Forgery (CSRF) vulnerability in Sami Ahmed Siddiqui HTTP Auth plugin <= 0.3.2 versions. | [email protected] | 6.3 | 0.08% | 2023-10-03 | 2024-11-21 |