LinuxServer records
5 published records for vendor linuxserver.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 20%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-674 Uncontrolled Recursion1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2025-50578Proof of concept | LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` alinuxserver · docker-heimdall · CWE-20 | Critical9.8 | — | 2.8% | Jul 30, 2025 |
39Monitor | CVE-2024-51358Proof of concept | An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new applicationCWE-918 | Critical9.8 | — | 1.0% | Nov 5, 2024 |
39Monitor | CVE-2023-51803No exploit | LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.CWE-674 | Critical9.8 | — | 0.7% | Mar 31, 2024 |
24Monitor | CVE-2025-54597Proof of concept | LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.linuxserver · heimdall application dashboard · CWE-79 | Medium6.1 | — | 0.6% | Jul 26, 2025 |
21Monitor | CVE-2022-47968No exploit | Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page.linuxserver · heimdall application dashboard · CWE-79 | Medium5.4 | — | 0.4% | Dec 27, 2022 |
- CVE-2025-5057840Plan
LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` a
CriticalCVSS 9.8Proof of conceptEPSS 3%linuxserver · docker-heimdallJul 30, 2025
- CVE-2024-5135839Monitor
An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application
CriticalCVSS 9.8Proof of conceptEPSS 1%Nov 5, 2024
- CVE-2023-5180339Monitor
LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.
CriticalCVSS 9.8No exploitEPSS 1%Mar 31, 2024
- CVE-2025-5459724Monitor
LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.
MediumCVSS 6.1Proof of conceptEPSS 1%linuxserver · heimdall application dashboardJul 26, 2025
- CVE-2022-4796821Monitor
Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page.
MediumCVSS 5.4No exploitEPSS 0%linuxserver · heimdall application dashboardDec 27, 2022