Skip to main content

Vendor/product archive

linecorp / line CVEs

Beta · best-effort

75 CVEs tagged to linecorp / line0 Critical, 25 High, 48 Medium, 2 Low, 0 Unrated.

CVE-2026-3861

Published Apr 16, 2026

LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insuffi…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14023

Published Dec 15, 2025

LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's user interface, which could create confusion abo…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14022

Published Dec 15, 2025

LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the appli…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14021

Published Dec 15, 2025

The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14020

Published Dec 15, 2025

LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not properly re-dis…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-14019

Published Dec 15, 2025

LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the full-screen warning prompt, potenti…

CVSS 3.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-5739

Published Jun 12, 2024

The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripting (XSS) where arbit…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48129

Published Jan 26, 2024

An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48135

Published Jan 26, 2024

An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48133

Published Jan 26, 2024

An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48132

Published Jan 26, 2024

An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48131

Published Jan 26, 2024

An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48130

Published Jan 26, 2024

An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48128

Published Jan 26, 2024

An issue in UNITED BOXING GYM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48127

Published Jan 26, 2024

An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48126

Published Jan 26, 2024

An issue in Luxe Beauty Clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44001

Published Jan 24, 2024

An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44000

Published Jan 24, 2024

An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43999

Published Jan 24, 2024

An issue in COLORFUL_laundry mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43998

Published Jan 24, 2024

An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43997

Published Jan 24, 2024

An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43996

Published Jan 24, 2024

An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43995

Published Jan 24, 2024

An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43994

Published Jan 24, 2024

An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43993

Published Jan 24, 2024

An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 75 CVEsPage 1 of 3