CVE-2025-69904
Last modified
CVE-2025-69904 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive system or application files.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive system or application files.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-69904?
How severe is CVE-2025-69904?
How do I fix CVE-2025-69904?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-69875A vulnerability exists in Quick Heal Total Security 23.0.0 i…7.8
- CVE-2025-6988The kallyas theme for WordPress is vulnerable to Stored Cros…6.4
- CVE-2025-6989The Kallyas theme for WordPress is vulnerable to arbitrary f…8.1
- CVE-2025-69893A side-channel vulnerability exists in the implementation of…4.6
- CVE-2025-6990The kallyas theme for WordPress is vulnerable to Remote Code…8.8
- CVE-2025-69902A command injection vulnerability in the minimal_wrapper.py …9.8
- CVE-2025-69906Monstra CMS v3.0.4 contains an arbitrary file upload vulnera…8.8
- CVE-2025-69907An unauthenticated information disclosure vulnerability exis…7.5
- CVE-2025-69908An unauthenticated information disclosure vulnerability in N…7.5
- CVE-2025-6991The kallyas theme for WordPress is vulnerable to Local File …7.5
- CVE-2025-6992Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-69929An issue in N3uron Web User Interface v.1.21.7-240207.1047 a…9.8
Are you affected by CVE-2025-69904?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
