Linkace is a self-hosted link management and bookmarking application that serves as a personal or organizational repository for web resources. Its vulnerability footprint concentrates in a small set of disclosures affecting the core product, with a recurring pattern of web-application input-handling and access-control weaknesses including cross-site scripting, server-side request forgery, sensitive-information exposure, and improper access controls. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linkace over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33953HIGH LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal | Mar 27, 2026 | 8.5 | 29 | NO | NO |
CVE-2025-59424HIGH LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerability has been identified on the /system/audit page. The appl | Sep 18, 2025 | 7.3 | 24 | NO | NO |
CVE-2026-33954MEDIUM LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-private link can be disclosed to a different authenticated u | Mar 27, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-30953MEDIUM LinkAce is a self-hosted archive to collect website links. When a user creates a link via POST /links, the server fetches HTML metadata from the provided URL (LinkRepository::creat | Mar 10, 2026 | 6.5 | 22 | NO | NO |
CVE-2025-62721MEDIUM LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class fail to implement proper author | Nov 4, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-62720MEDIUM LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to export the entire database of links from all users in the system | Nov 4, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-56508HIGH LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerability exists in the LinkAce. This issue occurs in the "Import Bo | Dec 27, 2024 | 7.6 | 22 | NO | NO |
CVE-2026-27458MEDIUM LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting vulnerability through the Atom feed endpoint for lists (/list | Feb 21, 2026 | 5.4 | 20 | NO | NO |
CVE-2025-62722MEDIUM LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) vulnerab | Nov 4, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-53838MEDIUM LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discovered in versions prior to 2.1.9 that allows an attacker to in | Sep 8, 2025 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linkace.
Media articles that mention a CVE ID that affects a product developed by Linkace — matched by CVE ID, not by vendor name.