LinkedIn records
6 published records for vendor linkedin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-449 The UI Performs the Wrong Action1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2021-4264No exploit | LinkedIn dustjs prototype pollutionlinkedin · dustjs · CWE-1321 | High8.8 | — | 1.1% | Dec 21, 2022 |
31Monitor | CVE-2008-3435No exploit | LinkedIn Browser Toolbar 3.0.3.1100 and earlier does not properly verify the authenticity of updates, which allows man-in-the-middle attackelinkedin · browser toolbar · CWE-94 | High7.5 | — | 1.8% | Aug 1, 2008 |
30Monitor | CVE-2024-28425No exploit | greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py.linkedin · greykite · CWE-434 | High7.5 | — | 0.6% | Mar 14, 2024 |
29Monitor | CVE-2007-3955Proof of concept | Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote alinkedin · toolbar | Medium6.8 | — | 8.2% | Jul 24, 2007 |
25Monitor | CVE-2021-26722No exploit | LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search barlinkedin · oncall · CWE-79 | Medium6.1 | — | 3.2% | Feb 5, 2021 |
21Monitor | CVE-2025-56139No exploit | LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replinkedin · linkedin · CWE-449 | Medium5.3 | — | 0.3% | Sep 3, 2025 |
- CVE-2021-426435Monitor
LinkedIn dustjs prototype pollution
HighCVSS 8.8No exploitEPSS 1%linkedin · dustjsDec 21, 2022
- CVE-2008-343531Monitor
LinkedIn Browser Toolbar 3.0.3.1100 and earlier does not properly verify the authenticity of updates, which allows man-in-the-middle attacke
HighCVSS 7.5No exploitEPSS 2%linkedin · browser toolbarAug 1, 2008
- CVE-2024-2842530Monitor
greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py.
HighCVSS 7.5No exploitEPSS 1%linkedin · greykiteMar 14, 2024
- CVE-2007-395529Monitor
Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote a
MediumCVSS 6.8Proof of conceptEPSS 8%linkedin · toolbarJul 24, 2007
- CVE-2021-2672225Monitor
LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar
MediumCVSS 6.1No exploitEPSS 3%linkedin · oncallFeb 5, 2021
- CVE-2025-5613921Monitor
LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user rep
MediumCVSS 5.3No exploitEPSS 0%linkedin · linkedinSep 3, 2025