Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-55944

Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a new browser tab, the embedded JavaScript executes. The issue affects both authenticated and unauthenticated users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.9%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2025-55944
  • Slinkapp » Slink » Version: 1.4.9
    cpe:2.3:a:slinkapp:slink:1.4.9
  • Slinkapp » Slink » Version: 1.5.1
    cpe:2.3:a:slinkapp:slink:1.5.1
  • Slinkapp » Slink » Version: 1.6.3
    cpe:2.3:a:slinkapp:slink:1.6.3


Contact Us

Shodan ® - All rights reserved