PT-2026-36191 · Linkstackorg · Linkstack

Aliaz

·

Published

2026-04-30

·

Updated

2026-05-01

·

CVE-2026-7501

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions LinkStackOrg LinkStack versions prior to 4.8.7
Description A weakness in the editPage() function within the app/Http/Controllers/UserController.php file allows for remote cross-site scripting (XSS), which occurs when a user-supplied value is included in a web page without proper validation or escaping. This is triggered by manipulating the pageDescription argument.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the editPage() function to minimize the risk of exploitation.

Exploit

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7501

Affected Products

Linkstack