Executive brief
YOURLS is vulnerable to XSS through JSONP and Callback request parameters
Affected products
- Packagist yourls/yourls
Junglewise Threat Intelligence
Severity: low · CVSS 3.1 · Published 2025-12-30
Technologies: yourls/yourls (Packagist). Vendors: Packagist.
YOURLS is vulnerable to XSS through JSONP and Callback request parameters