Slinkapp's vulnerability profile centers on its Slink product, a narrowly scoped application where the observed weakness pattern reflects input-handling and output-encoding issues characteristic of web-facing software. The recurring signal is cross-site scripting vulnerability, a class endemic to web applications where user input reaches the rendered page without proper neutralization. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Slinkapp over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55944MEDIUM Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a new browser tab, the embedded JavaScript executes. The issue | Sep 3, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Slinkapp.
Media articles that mention a CVE ID that affects a product developed by Slinkapp — matched by CVE ID, not by vendor name.