Linuxserver
linuxserver
3 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to...Show more |
1Linuxserver 1Heimdall Application Dashboard Jun 17, 2026 Jul 27, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter. |
1Linuxserver 1Heimdall Application Dashboard Jun 17, 2026 Dec 27, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page. |