Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Kovah — Vulnerabilities & Security Advisories 19

Browse all 19 CVE security advisories affecting Kovah. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kovah serves as a penetration testing tool primarily used for identifying security vulnerabilities in web applications and network systems. Historically, it has been associated with common vulnerability classes including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. The tool has been noted for its extensive exploit capabilities, with 15 CVEs recorded to date. While no major public security incidents have been directly attributed to Kovah, its widespread use in both defensive and offensive security contexts has raised concerns about potential misuse. The tool's comprehensive nature makes it valuable for security professionals but also increases the risk of exploitation by malicious actors if not properly secured.

Top products by Kovah: LinkAce
CVE ID Title CVSS Severity Published
CVE-2026-49436 LinkAce vulnerable to stored XSS via 'javascript:' URI in Bulk Link API — LinkAce CWE-79 7.3 High 2026-08-20
CVE-2026-45342 LinkAce: IDOR in Update Policies Allows Any Authenticated User to Overwrite Other Users' Links, Lists, Tags, and Notes — LinkAce CWE-639 - - 2026-05-28
CVE-2026-45343 LinkAce - Stored XSS via Unsanitized SSO User's Name Rendered in Admin Audit Log Allows Session Hijacking — LinkAce CWE-79 - - 2026-05-28
CVE-2026-45344 LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instances — LinkAce CWE-74 8.1 High 2026-05-28
CVE-2026-40905 LinkAce: Password Reset Poisoning via X-Forwarded-Host Header Injection Leading to Account Takeover — LinkAce CWE-601 8.1 High 2026-04-21
CVE-2026-35516 LinkAce has SSRF via CheckLinksCommand - Link URL Update Bypasses laravel-html-meta Protection — LinkAce CWE-918 5.0 Medium 2026-04-07
CVE-2026-33954 LinkAce discloses private notesto unauthorized authenticated users via the web link detail page — LinkAce CWE-285 6.5 Medium 2026-03-27
CVE-2026-33953 LinkAce's SSRF protection can be bypassed via internal hostname resolution in LinkAce — LinkAce CWE-918 8.5 High 2026-03-27
CVE-2026-30954 LinkAce has a Cross-User Tag/List Attachment IDOR in processTaxonomy() — LinkAce CWE-639 4.3AI Medium AI 2026-03-10
CVE-2026-30953 LinkAce affected by SSRF via link creation: NoPrivateIpRule not applied to LinkStoreRequest — LinkAce CWE-918 7.7 High 2026-03-10
CVE-2026-27458 LinkAce: Stored XSS in Atom Feed via CDATA Escape in List Description — LinkAce CWE-80 5.4AI Medium AI 2026-02-21
CVE-2025-62722 LinkAce: Stored XSS Vulnerability in Link Title Field Through Social Media Sharing Feature — LinkAce CWE-79 5.4AI Medium AI 2025-11-04
CVE-2025-62721 LinkAce: Authorization Bypass Allows Unauthorized Access to All Private Links, Lists, and Tags — LinkAce CWE-200 4.3AI Medium AI 2025-11-04
CVE-2025-62720 LinkAce: Data Exfiltration via Export Functions Allow Access to All Users' Private Links — LinkAce CWE-200 4.3AI Medium AI 2025-11-04
CVE-2025-62719 LinkAce: Limited Server-Side Request Forgery (SSRF) in Keyword Fetching Functionality — LinkAce CWE-918 4.3AI Medium AI 2025-11-04
CVE-2025-59424 LinkAce Vulnerable to Stored XSS on the Audit Page — LinkAce CWE-79 7.3 High 2025-09-18
CVE-2025-53838 LinkAce has a Stored One Click XSS vulnerability — LinkAce CWE-79 5.4AI Medium AI 2025-09-08
CVE-2024-56508 File Upload Vulnerability Leading to XSS in LinkAce v1.15.5 — LinkAce CWE-434 7.6 High 2024-12-27
CVE-2024-56507 Reflected Cross-Site Scripting (XSS) Vulnerability in LinkAce — LinkAce CWE-79 4.6 Medium 2024-12-27

This page lists every published CVE security advisory associated with Kovah. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.