Linqi is a niche web application platform whose vulnerability profile concentrates on a single product and skews strongly toward critical-severity outcomes. The recurring weakness classes—sensitive information exposure, PHP remote file inclusion, cross-site scripting, LDAP injection, and server-side request forgery—reflect the input-handling and access-control demands of web-facing applications and server-side request routing. Defenders tracking this vendor should prioritize patches addressing these web-tier vulnerabilities; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by linqi GmbH over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-33868CRITICAL An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection. | May 14, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-33863CRITICAL An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion. | May 14, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-33865HIGH An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endpoints. | May 14, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-33866MEDIUM An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS. | May 14, 2024 | 5.5 | 17 | NO | NO |
CVE-2024-33864MEDIUM An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF doc | May 14, 2024 | 5.9 | 17 | NO | NO |
CVE-2024-33867MEDIUM An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt. | May 14, 2024 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by linqi GmbH.
Media articles that mention a CVE ID that affects a product developed by linqi GmbH — matched by CVE ID, not by vendor name.