VYPR

Shlink

by Shlinkio

Source repositories

CVEs (4)

  • CVE-2026-50887CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.

  • CVE-2026-18737MedAug 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. Attackers can craft a malicious direction…

  • CVE-2026-18736MedAug 3, 2026
    risk 0.33cvss 5.0epss 0.00

    Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs…

  • CVE-2026-18738MedAug 3, 2026
    risk 0.24cvss 4.7epss 0.00

    Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers beginning with…