LinkAce is a self-hosted archive to collect website links. In 2.1.0 and earlier, the processTaxonomy() method in LinkRepository.php allows authenticated users to attach other users' private tags and lists to their own links by passing integer IDs.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kovah
Kovah linkace |
|
| Vendors & Products |
Kovah
Kovah linkace |
Tue, 10 Mar 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LinkAce is a self-hosted archive to collect website links. In 2.1.0 and earlier, the processTaxonomy() method in LinkRepository.php allows authenticated users to attach other users' private tags and lists to their own links by passing integer IDs. | |
| Title | LinkAce has a Cross-User Tag/List Attachment IDOR in processTaxonomy() | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-10T20:40:31.011Z
Updated: 2026-03-11T14:30:40.687Z
Reserved: 2026-03-07T17:34:39.981Z
Link: CVE-2026-30954
Updated: 2026-03-11T14:29:54.866Z
Status : Awaiting Analysis
Published: 2026-03-10T21:16:48.513
Modified: 2026-03-11T13:52:47.683
Link: CVE-2026-30954
No data.
ReportizFlow