CVE-2025-62722 HIGH

CVE-2025-62722: LinkAce: Stored XSS Vulnerability in Link Title Field Through Social Media Sharing Feature

Vendor Kovah
Product LinkAce
Weakness CWE-79 · XSS
Published November 4, 2025
Last update November 5, 2025

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functionality contains a Stored Cross-Site Scripting (XSS) vulnerability that allows any authenticated user to inject arbitrary JavaScript by creating a link with malicious HTML in the title field. When a user views the link details page and the shareable links are rendered, the malicious JavaScript executes in their browser. This vulnerability affects multiple sharing services and can be exploited to steal session cookies, perform actions on behalf of users, or deliver malware. This issue is fixed in version 2.4.0.

Key dates

02Disclosure timeline

November 4, 2025 CVE published
November 5, 2025 Record updated