Linkstack is a niche link-aggregation and profile platform whose vulnerability exposure centers on session management, server-side request handling, and authentication-recovery mechanisms. The recurring weakness classes—insufficient session expiration, server-side request forgery, and weak password-recovery design—reflect application-layer security risks typical of web-facing services handling user identity and access control. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linkstack over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5838CRITICAL Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9. | Oct 29, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-5840HIGH Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9. | Oct 29, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-35451MEDIUM LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF. | Nov 29, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linkstack.
Media articles that mention a CVE ID that affects a product developed by Linkstack — matched by CVE ID, not by vendor name.