« Back to list

Linkstack

Linkstack: vulnerabilities and CVEs

Linkstack has 6 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months3
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-69904Medium (4.9)0.35%—Sep 11, 2026
Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access…
CVE-2026-7502Low (2.1)0.44%—Apr 30, 2026
A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Management Endpoint.…
CVE-2026-7501Low (2)0.35%—Apr 30, 2026
A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can…
CVE-2024-35451Medium (4.8)0.32%—Nov 29, 2024
LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF.
CVE-2023-5840High (8.8)0.67%—Oct 29, 2023
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.
CVE-2023-5838Critical (9.8)0.50%—Oct 29, 2023
Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.