Linkace

Linkace

14 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 07.04.2026 15:14:45
  • Zuletzt bearbeitet 14.04.2026 20:27:53

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand::checkLink do not check for private IPs. An authenticated user can read responses from internal services (AWS IMDSv1, cloud metada...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 27.03.2026 21:23:30
  • Zuletzt bearbeitet 31.03.2026 18:03:35

LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-private link can be disclosed to a different authenticated user via the web interface. The API appears to correctly enforce note v...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 27.03.2026 21:22:03
  • Zuletzt bearbeitet 31.03.2026 17:57:08

LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal-only resources when those resources are referenced through an interna...

  • EPSS 0.04%
  • Veröffentlicht 10.03.2026 20:40:31
  • Zuletzt bearbeitet 17.03.2026 16:13:55

LinkAce is a self-hosted archive to collect website links. In 2.1.0 and earlier, the processTaxonomy() method in LinkRepository.php allows authenticated users to attach other users' private tags and lists to their own links by passing integer IDs.

  • EPSS 0.04%
  • Veröffentlicht 10.03.2026 20:38:48
  • Zuletzt bearbeitet 17.03.2026 16:13:30

LinkAce is a self-hosted archive to collect website links. When a user creates a link via POST /links, the server fetches HTML metadata from the provided URL (LinkRepository::create() calls HtmlMeta::getFromUrl()). The LinkStoreRequest validation rul...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 21.02.2026 06:54:41
  • Zuletzt bearbeitet 24.02.2026 15:03:33

LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting vulnerability through the Atom feed endpoint for lists (/lists/feed). An authenticated user can inject a CDATA-breaking payload int...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 04.11.2025 22:31:46
  • Zuletzt bearbeitet 25.11.2025 18:45:24

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) vulnerability that allows any authenticated user to inject arbitrary JavaScrip...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 04.11.2025 22:07:09
  • Zuletzt bearbeitet 10.11.2025 19:56:06

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class fail to implement proper authorization checks, allowing any authenticated user to access all links, l...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 04.11.2025 22:03:09
  • Zuletzt bearbeitet 10.11.2025 19:57:02

LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to export the entire database of links from all users in the system, including private links that should only be accessible to their owne...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 04.11.2025 21:57:15
  • Zuletzt bearbeitet 10.11.2025 19:57:35

LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function in the FetchController class accepts user-provided URLs and makes HTTP requests to them without validating that the destination i...