Confidence
Medium. Based on ~25 public sources; many review snippets were truncated, so quotes are partial.
Pricing
Free
Self-hosted
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Sources & method
Analyzed 9/21/2026 - 11 sources - Multiple CVEs across 2024–2026 (SSRF, stored XSS, information disclosure); fixed in newer releases — run the latest version.
official x4review x4security x3
- SSRF vulnerability (CVE-2026-30953), Rated high severity by third-party trackers.
- Stored XSS via javascript: URI in Bulk Link API (CVE-2026-49436), Authenticated stored XSS through link URLs.
- Stored XSS prior to 2.5.6 (CVE-2026-45343), Patched in version 2.5.6.
- File upload XSS in v1.15.5 (GHSA-2wvv-4576-8862), File upload leading to cross-site scripting; fixed after disclosure.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.