cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forlink-library link-library

Direction: ascending
Jun 07, 2024

Link Library # CVE-2021-25093

CVE, Research URL

CVE-2021-25093

Application

Link Library

Date
Feb 01, 2022
Research Description
The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request
Affected versions
max 7.2.9.
Status
vulnerable

Link Library # CVE-2021-25091

CVE, Research URL

CVE-2021-25091

Application

Link Library

Date
Feb 01, 2022
Research Description
The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
Affected versions
max 7.2.9.
Status
vulnerable

Link Library # CVE-2021-25092

CVE, Research URL

CVE-2021-25092

Application

Link Library

Date
Feb 01, 2022
Research Description
The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack
Affected versions
max 7.2.8.
Status
vulnerable

Link Library # CVE-2022-4199

CVE, Research URL

CVE-2022-4199

Application

Link Library

Date
Jan 16, 2023
Research Description
The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 7.4.1.
Status
vulnerable

Link Library # CVE-2024-1559

CVE, Research URL

CVE-2024-1559

Application

Link Library

Date
Feb 20, 2024
Research Description
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 7.6.1.
Status
vulnerable

Link Library # CVE-2024-4281

CVE, Research URL

CVE-2024-4281

Application

Link Library

Date
May 08, 2024
Research Description
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 7.7.
Status
vulnerable

Link Library # CVE-2024-2325

CVE, Research URL

CVE-2024-2325

Application

Link Library

Date
Apr 10, 2024
Research Description
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all versions up to, and including, 7.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 7.6.7.
Status
vulnerable

Link Library # CVE-2024-29123

CVE, Research URL

CVE-2024-29123

Application

Link Library

Date
Mar 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.
Affected versions
max 7.6.1.
Status
vulnerable

Link Library # CVE-2024-24879

CVE, Research URL

CVE-2024-24879

Application

Link Library

Date
Feb 08, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.5.13.
Affected versions
max 7.6.
Status
vulnerable

Link Library # CVE-2024-24875

CVE, Research URL

CVE-2024-24875

Application

Link Library

Date
Feb 12, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.
Affected versions
max 7.6.
Status
vulnerable
Jun 10, 2024

Link Library # CVE-2024-35687

CVE, Research URL

CVE-2024-35687

Application

Link Library

Date
Jun 08, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.3.
Affected versions
max 7.6.4.
Status
vulnerable
Jul 15, 2024

Link Library # CVE-2024-38711

CVE, Research URL

CVE-2024-38711

Application

Link Library

Date
Jul 20, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.7.1.
Affected versions
max 7.7.2.
Status
vulnerable
Jan 22, 2025

Link Library # CVE-2024-13404

CVE, Research URL

CVE-2024-13404

Application

Link Library

Date
Jan 21, 2025
Research Description
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 7.7.3.
Status
vulnerable
Apr 05, 2025

Link Library # CVE-2025-2889

CVE, Research URL

CVE-2025-2889

Application

Link Library

Date
Apr 05, 2025
Research Description
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 7.8.
Status
vulnerable
Apr 24, 2025

Link Library # CVE-2025-46237

CVE, Research URL

CVE-2025-46237

Application

Link Library

Date
Apr 22, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Stored XSS.This issue affects Link Library: from n/a through <= 7.8.
Affected versions
max 7.8.1.
Status
vulnerable
Jan 10, 2026

Link Library # CVE-2025-68600

CVE, Research URL

CVE-2025-68600

Application

Link Library

Date
Dec 24, 2025
Research Description
Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Request Forgery.This issue affects Link Library: from n/a through <= 7.8.7.
Affected versions
max 7.8.8.
Status
vulnerable
May 02, 2026

Link Library # CVE-2026-40779

CVE, Research URL

CVE-2026-40779

Application

Link Library

Date
-
Research Description
Link Library [link-library] < 7.8.9 CVE-2026-40779
Affected versions
max 7.8.9.
Status
vulnerable
Jun 15, 2026

Link Library # f9195edd392c482128bd01ac85be669899311e02

Application

Link Library

Date
Aug 14, 2017
Research Description
Link Library [link-library] < 5.9.13.27 Link Library <= 5.9.13.26 – SQL Injection The Link Library plugin for WordPress is vulnerable to generic SQL Injection via the "$_GET[‘linkid’]" parameter in versions up to, and including, 5.9.13.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrative privileges and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 5.9.13.27.
Status
vulnerable

Link Library # 12d8f6a188e7cdb53c9b166e77b8f46e97b9bb59

Application

Link Library

Date
Aug 16, 2017
Research Description
Link Library [link-library] < 5.9.13.27 WordPress Link-Library plugin <=5.9.13.26 – Authenticated SQL Injection vulnerability Authenticated SQL Injection vulnerability found by Lenon Leite in WordPress Link-Library plugin version 5.9.13.26 and earlier versions. Update WordPress Link-Library plugin to the latest available version (at least 5.9.13.27).
Affected versions
max 5.9.13.27.
Status
vulnerable

Link Library # 40386b83-a47e-40e0-82e0-f7d299187d56

Application

Link Library

Date
-
Research Description
Link Library [link-library] < 5.9.12.30 Link Library &lt;= 5.9.12.29 - Authenticated Reflected Cross-Site Scripting (XSS) The Link Library WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
Affected versions
max 5.9.12.30.
Status
vulnerable

Link Library # 01b7422e-7d20-4481-98c5-06f3c9ef557b

Application

Link Library

Date
-
Research Description
Link Library [link-library] < 5.0.9 Link Library 5.0.8 - wp-content/plugins/link-library/tracker.php id Parameter SQL Injection The Link Library WordPress plugin was affected by a wp-content/plugins/link-library/tracker.php id Parameter SQL Injection security vulnerability.
Affected versions
max 5.0.9.
Status
vulnerable

Link Library # 40239f22-520e-4ed2-9a44-34521ac6a117

Application

Link Library

Date
-
Research Description
Link Library [link-library] < 5.0.9 Link Library 5.0.8 - wp-content/plugins/link-library/tracker.php id Parameter XSS The Link Library WordPress plugin was affected by a wp-content/plugins/link-library/tracker.php id Parameter XSS security vulnerability.
Affected versions
max 5.0.9.
Status
vulnerable

Link Library # 7f019b1e5164b0528a45d919d6d3250f1d531e4d

Application

Link Library

Date
Aug 15, 2016
Research Description
Link Library [link-library] < 5.9.12.30 Link Library <= 5.9.12.29 - Reflected Cross-Site Scripting The link-library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'successimportcount’ parameter in versions up to, and including, 5.9.12.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 5.9.12.30.
Status
vulnerable

Link Library # 4b3c7fdf-47d1-4539-9df3-29ec76cf6ea6

Application

Link Library

Date
-
Research Description
Link Library [link-library] < 5.1.7 Link Library 5.1.6 - link-library-ajax.php Multiple Parameter SQL Injection The Link Library WordPress plugin was affected by a link-library-ajax.php Multiple Parameter SQL Injection security vulnerability.
Affected versions
max 5.1.7.
Status
vulnerable

Link Library # 7e67721c48c77baac1f0f2b94080ab47629eccda

Application

Link Library

Date
May 15, 2015
Research Description
Link Library [link-library] < 5.0.9 WordPress Link Library Plugin <= 5.0.8 - Cross Site Scripting Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Vulnerable parameter "id". Update the plugin.
Affected versions
max 5.0.9.
Status
vulnerable

Link Library # d02a5551d05ef3a99e0c1e9245d7caf0eb200944

Application

Link Library

Date
Sep 24, 2011
Research Description
Link Library [link-library] < 5.2.2 WordPress Link Library Plugin <= 5.2.1 - SQL Injection Link Library plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.
Affected versions
max 5.2.2.
Status
vulnerable

Link Library # cadd8fd5ddf01d7cb65b455afdb299c314d57c71

Application

Link Library

Date
Nov 08, 2014
Research Description
Link Library [link-library] < 5.8.11 Link Library <= 5.8.10.6 - Reflected Cross-Site Scripting The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘searchll’ parameter in versions up to, and including, 5.8.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 5.8.11.
Status
vulnerable

Link Library # 78f46c237c50389a2652d9a594b3c26cc90dcf4f

Application

Link Library

Date
Aug 16, 2016
Research Description
Link Library [link-library] < 5.9.12.30 WordPress Link Library Plugin <= 5.9.12.29 - Cross Site Scripting Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
Affected versions
max 5.9.12.30.
Status
vulnerable

Link Library # 12d86116cffeffe7e1e41643078cfaf093414f7f

Application

Link Library

Date
May 15, 2015
Research Description
Link Library [link-library] < 5.1.7 WordPress Link Library Plugin <= 5.1.6 - SQL Injection Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Update the plugin.
Affected versions
max 5.1.7.
Status
vulnerable

Link Library # a3418d38c0d3af402b9695c702dc069da5bd7223

Application

Link Library

Date
May 15, 2015
Research Description
Link Library [link-library] < 5.0.9 WordPress Link Library Plugin <= 5.0.8 - SQL Injection This plugin is prone to SQL injection in wp-content/plugins/link-library/tracker.php id parameter. Update the plugin.
Affected versions
max 5.0.9.
Status
vulnerable

Link Library # bfc1a75e-b001-43f2-b618-7c1e2a67012b

Application

Link Library

Date
-
Research Description
Link Library [link-library] < 5.9.13.27 Link-Library &lt;= 5.9.13.26 &ndash; Authenticated SQL Injection Type user access: admin user. $_GET[&lsquo;linkid&rsquo;] is not escaped.
Affected versions
max 5.9.13.27.
Status
vulnerable

Link Library # e8bfb06f-6ad7-456c-a05d-725868a0f3a6

Application

Link Library

Date
-
Research Description
Link Library [link-library] < 5.7.9.7 Link Library &lt;= 5.2.1 - SQL Injection The Link Library WordPress plugin was affected by a SQL Injection security vulnerability.
Affected versions
max 5.7.9.7.
Status
vulnerable
Aug 01, 2026

Link Library # CVE-2026-18197

CVE, Research URL

CVE-2026-18197

Application

Link Library

Date
Jul 29, 2026
Research Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Library: before 7.9.4.
Affected versions
max 7.9.4.
Status
vulnerable
Aug 04, 2026

Link Library # CVE-2026-16532

CVE, Research URL

CVE-2026-16532

Application

Link Library

Date
Aug 03, 2026
Research Description
The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
Affected versions
max 7.9.3.
Status
vulnerable