Linuxserver
Products
3- 4 CVEs
- 2 CVEs
- 1 CVE
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-50578 | Cri | 0.64 | 9.8 | 0.03 | Jul 30, 2025 | LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks.… | ||
| CVE-2024-51358 | Cri | 0.64 | 9.8 | 0.01 | Nov 5, 2024 | An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application. | ||
| CVE-2023-51803 | Cri | 0.57 | 9.8 | 0.01 | Apr 1, 2024 | LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring. | ||
| CVE-2022-47968 | Med | 0.35 | 5.4 | 0.00 | Dec 27, 2022 | Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page. | ||
| CVE-2025-54597 | Hig | 0.00 | 7.2 | 0.01 | Jul 27, 2025 | LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter. |
- risk 0.64cvss 9.8epss 0.03
LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks.…
- risk 0.64cvss 9.8epss 0.01
An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.
- risk 0.57cvss 9.8epss 0.01
LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.
- risk 0.35cvss 5.4epss 0.00
Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page.
- risk 0.00cvss 7.2epss 0.01
LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.