Vulnerability Details CVE-2025-55944
                Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a new browser tab, the embedded JavaScript executes. The issue affects both authenticated and unauthenticated users.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.001
                        
                    
                    
                        
                            EPSS Ranking 24.4%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 6.1
                        
                    
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2025-55944
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:slinkapp:slink:1.4.9
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:slinkapp:slink:1.5.1
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:a:slinkapp:slink:1.6.3