CVE 8.7 HIGH

LinkAce: Stored XSS Vulnerability in Link Title Field Through Social Media Sharing Feature_CVE-2025-62722

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Description

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) vulnerability that allows any authenticated user to inject arbitrary JavaScript by creating a link with malicious HTML in the title field. When a user views the link details page and the shareable links are rendered, the malicious JavaScript executes in their browser. This vulnerability affects multiple sharing services and can be exploited to steal session cookies, perform actions on behalf of users, or deliver malware. This issue is fixed in version 2.4.0.

AI Analysis

Stored Cross-Site Scripting (XSS) vulnerability in the social media sharing functionality of LinkAce, allowing authenticated users to inject arbitrary JavaScript and potentially steal session cookies or deliver malware.

Basic Information

ID CVE-2025-62722
Source GitHub_M
Published Nov 4, 2025 at 22:31

Affected Product

Vendor Kovah
Product LinkAce
Version < 2.4.0
Affected Versions Kovah LinkAce < 2.4.0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor Kovah
Product LinkAce
Version 2.3.1 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.