Heimdall Application Dashboard
by Linuxserver
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-47968 | Med | 0.35 | 5.4 | 0.00 | Dec 27, 2022 | Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page. | ||
| CVE-2025-54597 | Hig | 0.00 | 7.2 | 0.01 | Jul 27, 2025 | LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter. |
- risk 0.35cvss 5.4epss 0.00
Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page.
- risk 0.00cvss 7.2epss 0.01
LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.