Vendor
Linkstack
Products
1
CVEs
4
Across products
4
Status
Private
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-35451 | Med | 0.31 | 4.8 | 0.00 | Nov 29, 2024 | LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF. | ||
| CVE-2025-69904 | Med | 0.25 | 4.9 | 0.00 | Sep 11, 2026 | Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive system or application files. | ||
| CVE-2023-5840 | Hig | 0.00 | 8.8 | 0.01 | Oct 29, 2023 | Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9. | ||
| CVE-2023-5838 | Cri | 0.00 | 9.8 | 0.01 | Oct 29, 2023 | Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9. |
- risk 0.31cvss 4.8epss 0.00
LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF.
- risk 0.25cvss 4.9epss 0.00
Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive system or application files.
- risk 0.00cvss 8.8epss 0.01
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.
- risk 0.00cvss 9.8epss 0.01
Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.