Known CVE
Heimdall Application Dashboard < 2.7.3 - Reflected XSS
LinuxServer.io Heimdall < 2.7.3 contains a stored XSS caused by improper sanitization of the \"q\" parameter, letting remote attackers execute scripts, exploit requires crafted input.
CVE-2025-54597
Medium2025CVSS 6.1CWE-79
cve2025 · heimdall · xss · reflected · linuxserver · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website