Known Vulnerabilities for Link-preview-js by OP-Engineering
Listed below are 10 of the newest known vulnerabilities associated with "Link-preview-js" by "OP-Engineering".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-43897 json | Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. There wa... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-42556 json | Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can cr... | Not Provided | 2026-05-08 | 2026-05-08 |
| CVE-2026-42181 json | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-supplied po... | Not Provided | 2026-05-08 | 2026-05-11 |
| CVE-2026-41929 json | Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview re... | Not Provided | 2026-05-07 | 2026-05-08 |
| CVE-2026-41461 json | SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview end... | Not Provided | 2026-04-23 | 2026-04-29 |
| CVE-2026-39670 json | Server-Side Request Forgery (SSRF) vulnerability in Brecht Visual Link Preview visual-link-preview allows Server Side Request... | Not Provided | 2026-04-08 | 2026-04-09 |
| CVE-2026-35036 json | Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link previ... | Not Provided | 2026-04-06 | 2026-04-07 |
| CVE-2026-33978 json | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exi... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-1086 json | The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... | Not Provided | 2026-03-07 | 2026-04-08 |
| CVE-2025-47548 json | Server-Side Request Forgery (SSRF) vulnerability in Varun Dubey Wbcom Designs - Activity Link Preview For BuddyPress activity... | Not Provided | 2025-05-07 | 2026-04-23 |