Home/Product/rankmath seo
Product

rankmath seo

18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-13229
< 1.0.236
The Rank Math SEO - AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a
4.3MEDIUM
CVE-2024-13227
< 1.0.236
The Rank Math SEO - AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th
6.4MEDIUM
CVE-2024-9314
< 1.0.229
The Rank Math SEO - AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versio
7.2HIGH
CVE-2024-9161
< 1.0.229
The Rank Math SEO - AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss
6.5MEDIUM
CVE-2024-4627
< 1.0.219
The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with
5.4MEDIUM
CVE-2023-23888
< 1.0.107.3
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rank Math Rank Math SEO allows Pat
7.6HIGH
CVE-2024-4335
< 1.0.218
The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textAlign’
6.4MEDIUM
CVE-2024-3665
< 1.0.217
The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's HowTo and F
6.4MEDIUM
CVE-2024-2536
< 1.0.215
The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HowTo block attribut
6.4MEDIUM
CVE-2024-25848
<= 8.1.2
In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affecte
5.9MEDIUM
CVE-2023-34375
<= 1.2.9
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web SEO by 10Web plugin <= 1.2.9 versions.
7.1HIGH
CVE-2023-32600
< 1.0.119.1
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Rank Math SEO plugin <= 1.0.119 versions.
6.5MEDIUM
CVE-2023-2224
< 1.2.7
The SEO by 10Web WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege
4.8MEDIUM
CVE-2022-36376
<= 1.0.95
Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.
6.8MEDIUM
CVE-2020-11515
<= 1.0.40.2
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to a
6.1MEDIUM
CVE-2020-11514
<= 1.0.40.2
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata
9.8CRITICAL
CVE-2019-14786
< 1.0.27.1
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-c
6.5MEDIUM
CVE-2007-3117
all versions
Cross-site scripting (XSS) vulnerability in the SEO module in ADPLAN 3 allows remote attackers to inject arbitrary web script or H
threatengine.sh