Junglewise Threat Intelligence

YOURLS is vulnerable to XSS through JSONP and Callback request parameters

Severity: low · CVSS 3.1 · Published 2025-12-30

Technologies: yourls/yourls (Packagist). Vendors: Packagist.

Executive brief

YOURLS is vulnerable to XSS through JSONP and Callback request parameters

Affected products

  • Packagist yourls/yourls

Related threats