CVE-2025-53838 - CVE House
Back to Database
Status published High CVE-2025-53838

LinkAce has a Stored One Click XSS vulnerability

Vulnerability Description

LinkAce is a self-hosted archive to collect website links. A stored cross-site scripting (XSS) vulnerability was discovered in versions prior to 2.1.9 that allows an attacker to inject arbitrary JavaScript, which is then executed in the context of a user's browser when the malicious link is clicked. This is a one-click XSS, meaning the victim only needs to click a crafted link — no further interaction is required. The application contains a stored XSS vulnerability due to insufficient filtering and escaping of user-supplied data inserted into link attributes. Malicious JavaScript code can be saved in the database along with the link and executed in the user’s browser when clicking the link, leading to arbitrary script execution within the context of the site. Version 2.1.9 fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-53838

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

LinkAce
Vulnerable Versions:
< 2.1.9

Timeline

Official Publish: September 8th, 2025
Last Modified: September 8th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)