📦 Linkace

by Linkace

🔍 What is Linkace?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-56508

HIGH CVSS 7.6 Dec 27, 2024

LinkAce versions before 1.15.6 contain a file upload vulnerability in the 'Import Bookmarks' feature that allows attackers to upload malicious HTML files containing JavaScript payloads. When users acc...

CVE-2026-27458

MEDIUM CVSS 5.4 Feb 21, 2026

This CVE describes a stored cross-site scripting (XSS) vulnerability in LinkAce's Atom feed endpoint for lists. An authenticated user can inject malicious payloads into list descriptions that execute ...

CVE-2025-62722

MEDIUM CVSS 5.4 Nov 4, 2025

This is a Stored Cross-Site Scripting (XSS) vulnerability in LinkAce's social media sharing functionality that allows authenticated users to inject malicious JavaScript into link titles. When other us...

CVE-2025-62721

MEDIUM CVSS 6.5 Nov 4, 2025

This vulnerability in LinkAce allows any authenticated user to access all links, lists, and tags from all users in the system, regardless of ownership or visibility settings. It affects LinkAce versio...

CVE-2025-62719

MEDIUM CVSS 4.3 Nov 4, 2025

This SSRF vulnerability in LinkAce allows authenticated attackers to make the application server send HTTP requests to internal network resources, enabling port scanning and service discovery. The imp...

CVE-2025-62720

MEDIUM CVSS 6.5 Nov 4, 2025

This vulnerability in LinkAce allows any authenticated user to export the entire database of links, including private links belonging to other users. The export functions fail to apply proper access c...

CVE-2025-53838

MEDIUM CVSS 5.4 Sep 8, 2025

LinkAce versions before 2.1.9 contain a stored cross-site scripting vulnerability that allows attackers to inject malicious JavaScript into link attributes. When users click on crafted links, the Java...

CVE-2024-56507

MEDIUM CVSS 4.6 Dec 27, 2024

LinkAce versions before 1.15.6 contain a reflected cross-site scripting (XSS) vulnerability in the 'Edit Link' module's URL field. Attackers can inject malicious JavaScript that executes in victims' b...