PT-2026-36191 · Linkstackorg · Linkstack

Aliaz

·

Published

2026-04-30

·

Updated

2026-04-30

·

CVE-2026-7501

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a pull request but has not reacted yet.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7501

Affected Products

Linkstack