Intel

AIKIDO-2025-10470

drupal/yoast_seo is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2025-7716 Published Jul 17, 2025

60

Medium Risk

This Affects:

PHPdrupal/yoast_seo
1.0.0 - 2.1.0
Fixed in 2.2.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to cross-site scripting (XSS). The module fails to properly escape metadata when rendering content previews, which can allow XSS attacks. This vulnerability is mitigated by the requirement that an attacker must be able to create content processed by the Real-Time SEO module.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/yoast_seo is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 2.1.0.

How to fix this

Upgrade the drupal/yoast_seo library to the patch version.