Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Linkedin

First CVE: Jul 24, 2007Active for: 19 yearsTotal CVEs: 6

LinkedIn's vulnerability footprint centers on a collection of web-facing and developer-oriented products including its primary platform, browser extensions, and open-source libraries such as DustJS and Greykite, alongside operational tools like OnCall. The recurring weakness classes—code injection, cross-site scripting, prototype pollution, and UI-action flaws—reflect the application-layer and front-end complexity characteristic of web platforms and client-side tooling, and public exploit code has an elevated tendency to emerge for vulnerabilities of these classes. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Linkedin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 24, 2007
18 years ago
Most Recent CVE
Sep 3, 2025
324 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-3955MEDIUM
Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a
Jul 24, 20076.830NOYES
CVE-2021-4264HIGH
A vulnerability was found in LinkedIn dustjs up to 2.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly con
Dec 21, 20228.828NONO
CVE-2024-28425HIGH
greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to exec
Mar 14, 20247.521NONO
CVE-2025-56139MEDIUM
LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces the original URL in a post or comm
Sep 3, 20255.320NONO
CVE-2008-3435HIGH
LinkedIn Browser Toolbar 3.0.3.1100 and earlier does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Troja
Aug 1, 20087.520NONO
CVE-2021-26722MEDIUM
LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar.
Feb 5, 20216.119NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network4 (66.7%)
Unknown2 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (50.0%)
High1 (16.7%)
Unknown2 (33.3%)
User Interaction
None2 (33.3%)
Unknown2 (33.3%)
Required2 (33.3%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None3 (50.0%)
Unknown2 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Linkedin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Linkedin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Linkedin's Products

View all 2 CNAs →

Top CWEs