Autolinks Project maintains a narrowly scoped web application focused on link management and integration, with observed vulnerabilities centered on web-layer input handling and request validation. The recurrent weakness classes—cross-site scripting and cross-site request forgery—are typical of web applications where user-supplied content and session state require careful sanitization and origin verification. Current severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Autolinks Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2782HIGH PHP remote file inclusion vulnerability in al_initialize.php for AutoLinks Pro 2.1 allows remote attackers to execute arbitrary PHP code via an "ftp://" URL in the alpath parameter | Sep 2, 2005 | 7.5 | 29 | NO | YES |
CVE-2022-1112MEDIUM The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers | Apr 18, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Autolinks Project.
Media articles that mention a CVE ID that affects a product developed by Autolinks Project — matched by CVE ID, not by vendor name.