Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Linkace

First CVE: Dec 27, 2024Active for: 2 yearsTotal CVEs: 14
23.3
VTI Score
Low

Linkace is a self-hosted link management and bookmarking application that serves as a personal or organizational repository for web resources. Its vulnerability footprint concentrates in a small set of disclosures affecting the core product, with a recurring pattern of web-application input-handling and access-control weaknesses including cross-site scripting, server-side request forgery, sensitive-information exposure, and improper access controls. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
4.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Linkace over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 27, 2024
18 months ago
Most Recent CVE
Apr 7, 2026
108 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33953HIGH
LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal
Mar 27, 20268.529NONO
CVE-2025-59424HIGH
LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerability has been identified on the /system/audit page. The appl
Sep 18, 20257.324NONO
CVE-2026-33954MEDIUM
LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-private link can be disclosed to a different authenticated u
Mar 27, 20266.522NONO
CVE-2026-30953MEDIUM
LinkAce is a self-hosted archive to collect website links. When a user creates a link via POST /links, the server fetches HTML metadata from the provided URL (LinkRepository::creat
Mar 10, 20266.522NONO
CVE-2025-62721MEDIUM
LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class fail to implement proper author
Nov 4, 20256.522NONO
CVE-2025-62720MEDIUM
LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to export the entire database of links from all users in the system
Nov 4, 20256.522NONO
CVE-2024-56508HIGH
LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerability exists in the LinkAce. This issue occurs in the "Import Bo
Dec 27, 20247.622NONO
CVE-2026-27458MEDIUM
LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting vulnerability through the Atom feed endpoint for lists (/list
Feb 21, 20265.420NONO
CVE-2025-62722MEDIUM
LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) vulnerab
Nov 4, 20255.420NONO
CVE-2025-53838MEDIUM
LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discovered in versions prior to 2.1.9 that allows an attacker to in
Sep 8, 20255.420NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
79%
21%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (57.1%)
Unknown0 (0.0%)
Required6 (42.9%)
Privileges Required
Low14 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Linkace.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Linkace — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Linkace's Products

View all 1 CNAs →

Top CWEs