LinkAce
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 19 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 27, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →LinkAce vulnerable to stored XSS via 'javascript:' URI in Bulk Link API
LinkAce: IDOR in Update Policies Allows Any Authenticated User to Overwrite Other Users' Links, Lists, Tags, and Notes
LinkAce - Stored XSS via Unsanitized SSO User's Name Rendered in Admin Audit Log Allows Session Hijacking
LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instances
LinkAce: Password Reset Poisoning via X-Forwarded-Host Header Injection Leading to Account Takeover
LinkAce has SSRF via CheckLinksCommand - Link URL Update Bypasses laravel-html-meta Protection
LinkAce discloses private notesto unauthorized authenticated users via the web link detail page
LinkAce's SSRF protection can be bypassed via internal hostname resolution in LinkAce
LinkAce has a Cross-User Tag/List Attachment IDOR in processTaxonomy()
LinkAce affected by SSRF via link creation: NoPrivateIpRule not applied to LinkStoreRequest
Monitor LinkAce in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.