CVE-2026-1293

Yoast SEO <= 26.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'yoast-schema' Block Attribute

The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `yoast-schema` block attribute in all versions up to, and including, 26.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 2,502,255 live websites that are affected by CVE-2026-1293.

Run a Free Instant Scan




Affected Software

Product  Yoast SEO
Category Search Engine Optimization
Vulnerable Domains2,502,255 live websites (61% of Yoast SEO install base)
Vulnerable Versions
  • from 0 through 26.8
Vulnerable Versions Count391 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Feb 6, 2026
  • Updated - Apr 8, 2026

Credits

  • suyoung kim (finder)

Website Distribution by Country

Number of websites using CVE-2026-1293
United States740,339 websites



Germany246,079 websites
France180,133 websites
GB123,473 websites
Italy123,427 websites
Netherlands103,400 websites
Spain78,841 websites
Russia75,657 websites
Poland69,706 websites
Canada52,998 websites

Website Distribution by TLD

Number of websites using CVE-2026-1293
.com1,031,487 websites
.de145,796 websites
.org95,504 websites
.nl95,397 websites
.it91,374 websites
.co.uk83,581 websites
.fr83,022 websites
.ru64,091 websites
.net59,901 websites
.pl53,774 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-1293

Top websites that are affected by CVE-2026-1293. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.org United States***
****************.com United States***
********.com United States***
*******.com United States***
*********.com United States***
*********.com United States***
***.********.com United States***
**********.com United States***
*********.com United States***
******.com United States***
See full domain list

FAQ

CVE-2026-1293 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Yoast SEO
A total of 2,502,255 websites have been identified as vulnerable to CVE-2026-1293, based on global website indexing conducted by WebTechSurvey.
The Yoast SEO is affected by the CVE-2026-1293 vulnerability.
Yoast SEO versions up to and including 26.8 are vulnerable to CVE-2026-1293.