LinkedIn's vulnerability footprint centers on a collection of web-facing and developer-oriented products including its primary platform, browser extensions, and open-source libraries such as DustJS and Greykite, alongside operational tools like OnCall. The recurring weakness classes—code injection, cross-site scripting, prototype pollution, and UI-action flaws—reflect the application-layer and front-end complexity characteristic of web platforms and client-side tooling, and public exploit code has an elevated tendency to emerge for vulnerabilities of these classes. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linkedin over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3955MEDIUM Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a | Jul 24, 2007 | 6.8 | 30 | NO | YES |
CVE-2021-4264HIGH A vulnerability was found in LinkedIn dustjs up to 2.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly con | Dec 21, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-28425HIGH greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to exec | Mar 14, 2024 | 7.5 | 21 | NO | NO |
CVE-2025-56139MEDIUM LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comm | Sep 3, 2025 | 5.3 | 20 | NO | NO |
CVE-2008-3435HIGH LinkedIn Browser Toolbar 3.0.3.1100 and earlier does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Troja | Aug 1, 2008 | 7.5 | 20 | NO | NO |
CVE-2021-26722MEDIUM LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar. | Feb 5, 2021 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linkedin.
Media articles that mention a CVE ID that affects a product developed by Linkedin — matched by CVE ID, not by vendor name.