Skip to content

Known CVE

Heimdall Application Dashboard < 2.7.3 - Reflected XSS

LinuxServer.io Heimdall < 2.7.3 contains a stored XSS caused by improper sanitization of the \"q\" parameter, letting remote attackers execute scripts, exploit requires crafted input.

CVE-2025-54597

Medium2025CVSS 6.1CWE-79

cve2025 · heimdall · xss · reflected · linuxserver · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website