Vulnerability Details CVE-2025-55944
Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a new browser tab, the embedded JavaScript executes. The issue affects both authenticated and unauthenticated users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.9%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2025-55944
-
cpe:2.3:a:slinkapp:slink:1.4.9
-
cpe:2.3:a:slinkapp:slink:1.5.1
-
cpe:2.3:a:slinkapp:slink:1.6.3