Altumcode's vulnerability profile centers on its 66biolinks web application, a link-management and bio-page platform, with observed weaknesses concentrated in web-layer input handling and session management including path traversal, cross-site scripting, and session fixation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Altumcode over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-69602CRITICAL A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a r | Jan 28, 2026 | 9.1 | 28 | NO | NO |
CVE-2025-69601MEDIUM A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are automatically extracted without va | Jan 28, 2026 | 6.5 | 20 | NO | NO |
CVE-2025-66939MEDIUM Cross Site Scripting vulnerability in 66biolinks by AltumCode v.61.0.1 allows an attacker to execute arbitrary code via a crafted favicon file | Jan 12, 2026 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Altumcode.
Media articles that mention a CVE ID that affects a product developed by Altumcode — matched by CVE ID, not by vendor name.