VYPR
Vendor

Linuxserver

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2025-50578CriJul 30, 2025
    risk 0.64cvss 9.8epss 0.03

    LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks.…

  • CVE-2024-51358CriNov 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.

  • CVE-2023-51803CriApr 1, 2024
    risk 0.57cvss 9.8epss 0.01

    LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.

  • CVE-2025-54597HigJul 27, 2025
    risk 0.00cvss 7.2epss 0.01

    LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.