CVE-2025-64759 is a high-severity stored Cross-Site Scripting (XSS) vulnerability in Homarr, an open-source dashboard, affecting versions prior to 1.43.3. An attacker can execute arbitrary JavaScript in a user's browser by uploading a malicious SVG file, potentially leading to full administrative access if an administrator views the compromised page. The CVSS score is 8.1 (HIGH), indicating a network-based attack with low complexity but requiring user interaction and high privileges, resulting in high confidentiality and integrity impacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.43.3CPE matchmatch criteria | cpe:2.3:a:homarr:homarr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.