VYPR
Medium severity6.1NVD Advisory· Published Sep 3, 2025· Updated Jun 17, 2026

CVE-2025-55944

CVE-2025-55944

Description

Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a new browser tab, the embedded JavaScript executes. The issue affects both authenticated and unauthenticated users.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Slinkapp/Slink3 versions
    cpe:2.3:a:slinkapp:slink:1.4.9:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:slinkapp:slink:1.4.9:*:*:*:*:*:*:*
    • cpe:2.3:a:slinkapp:slink:1.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:slinkapp:slink:1.6.3:*:*:*:*:*:*:*
  • Slink/Slinkcpe-rescue

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.