Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

LinkAce — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in LinkAce, with AI-generated Chinese analysis, references, and POCs.

This page serves as a comprehensive vulnerability aggregation resource for LinkAce, a self-hosted bookmarking and link management application developed by Antiloop. It consolidates security issues related to weaknesses commonly found in PHP web applications, including Cross-Site Scripting (XSS), SQL Injection, and improper access control mechanisms. The database covers historical and recent disclosures ranging from early alpha releases through stable production versions, capturing both critical remote code execution flaws and lower-severity configuration errors reported by independent security researchers and bug bounty platforms. Users visiting this section can track the vendor’s advisory history to understand how quickly patches are deployed for different severity levels. Additionally, the page allows analysts to study specific weakness classes in the context of this software, revealing how architectural decisions in LinkAce may influence its attack surface. Readers can also look up a product’s vulnerability history to assess its overall security posture over time, identifying trends in bug frequency and resolution speed. This information supports security teams in evaluating risk exposure and prioritizing updates based on verified data rather than hearsay. By aggregating these findings in one location, the page facilitates a clearer understanding of the application’s security lifecycle. It helps developers and users alike to recognize common pitfalls in open-source PHP projects and apply relevant mitigation strategies. The content is structured to enable efficient querying and comparison, ensuring that stakeholders can make informed decisions regarding deployment, patching, and long-term maintenance of their LinkAce instances without relying on scattered external sources.

Vendor: Kovah

CVE ID Title CVSS Severity Published
CVE-2026-49436 LinkAce vulnerable to stored XSS via 'javascript:' URI in Bulk Link API CWE-79 7.3 High 2026-08-20
CVE-2026-45342 LinkAce: IDOR in Update Policies Allows Any Authenticated User to Overwrite Other Users' Links, Lists, Tags, and Notes CWE-639 - - 2026-05-28
CVE-2026-45343 LinkAce - Stored XSS via Unsanitized SSO User's Name Rendered in Admin Audit Log Allows Session Hijacking CWE-79 - - 2026-05-28
CVE-2026-45344 LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instances CWE-74 8.1 High 2026-05-28
CVE-2026-40905 LinkAce: Password Reset Poisoning via X-Forwarded-Host Header Injection Leading to Account Takeover CWE-601 8.1 High 2026-04-21
CVE-2026-35516 LinkAce has SSRF via CheckLinksCommand - Link URL Update Bypasses laravel-html-meta Protection CWE-918 5.0 Medium 2026-04-07
CVE-2026-33954 LinkAce discloses private notesto unauthorized authenticated users via the web link detail page CWE-285 6.5 Medium 2026-03-27
CVE-2026-33953 LinkAce's SSRF protection can be bypassed via internal hostname resolution in LinkAce CWE-918 8.5 High 2026-03-27
CVE-2026-30954 LinkAce has a Cross-User Tag/List Attachment IDOR in processTaxonomy() CWE-639 4.3AI Medium AI 2026-03-10
CVE-2026-30953 LinkAce affected by SSRF via link creation: NoPrivateIpRule not applied to LinkStoreRequest CWE-918 7.7 High 2026-03-10
CVE-2026-27458 LinkAce: Stored XSS in Atom Feed via CDATA Escape in List Description CWE-80 5.4AI Medium AI 2026-02-21
CVE-2025-62722 LinkAce: Stored XSS Vulnerability in Link Title Field Through Social Media Sharing Feature CWE-79 5.4AI Medium AI 2025-11-04
CVE-2025-62721 LinkAce: Authorization Bypass Allows Unauthorized Access to All Private Links, Lists, and Tags CWE-200 4.3AI Medium AI 2025-11-04
CVE-2025-62720 LinkAce: Data Exfiltration via Export Functions Allow Access to All Users' Private Links CWE-200 4.3AI Medium AI 2025-11-04
CVE-2025-62719 LinkAce: Limited Server-Side Request Forgery (SSRF) in Keyword Fetching Functionality CWE-918 4.3AI Medium AI 2025-11-04
CVE-2025-59424 LinkAce Vulnerable to Stored XSS on the Audit Page CWE-79 7.3 High 2025-09-18
CVE-2025-53838 LinkAce has a Stored One Click XSS vulnerability CWE-79 5.4AI Medium AI 2025-09-08
CVE-2024-56508 File Upload Vulnerability Leading to XSS in LinkAce v1.15.5 CWE-434 7.6 High 2024-12-27
CVE-2024-56507 Reflected Cross-Site Scripting (XSS) Vulnerability in LinkAce CWE-79 4.6 Medium 2024-12-27

All 19 known CVE vulnerabilities affecting LinkAce with full Chinese analysis, references, and POCs where available.