Linuxserver

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 5
    Known Exploited: 0
    3
    Critical Level Threats
    1
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-50578

    LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading of external resources from attacker-controlled domains and unintended redirection of users, potentially enabling phishing, UI redress, and session theft. The vulnerability exists due to insufficient validation and trust of untrusted input, affecting the integrity and trustworthiness of the application.

    Last Modified: Aug 25, 2025
    Published: Jul 30, 2025

    CVE-2025-54597

    LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.

    Last Modified: Aug 07, 2025
    Published: Jul 27, 2025

    CVE-2024-51358

    An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.

    Last Modified: Apr 15, 2026
    Published: Nov 05, 2024

    CVE-2023-51803

    LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.

    Last Modified: Apr 15, 2026
    Published: Mar 31, 2024

    CVE-2022-47968

    Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page.

    Last Modified: Apr 11, 2025
    Published: Dec 27, 2022
    Items Per Page
    Linuxserver Vulnerabilities & Security CVEs | CVE-DB