Homarr is a dashboard and home-server management application with a concentrated vulnerability footprint centered on its single core product, where vulnerabilities skew toward serious outcomes with an elevated tendency toward confirmed in-the-wild exploitation. The recurring exposure reflects the application's web-facing and server-side integration role, clustering around input-validation weaknesses, server-side request forgery, embedded malicious code, sensitive information leakage, and cross-site scripting—the characteristic flaws of a centralized orchestration interface handling untrusted requests and managing downstream services. Defenders should treat this vendor's advisories as impactful to the home-server and automation community; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Homarr over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54313HIGH eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that | Jul 19, 2025 | 7.5 | 65 | YES | NO |
CVE-2026-33510HIGH Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login page. The application improper | Apr 6, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-27796HIGH Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing unauthenticated users to retrieve | Mar 7, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-67493CRITICAL Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege escalation and getting access to groups of other users due to | Dec 17, 2025 | 9.0 | 25 | NO | NO |
CVE-2025-64759MEDIUM Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a user's browser, with minimal or no | Nov 19, 2025 | 6.1 | 22 | NO | NO |
CVE-2026-27797MEDIUM Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability allows a remote attacker to force the Homarr server | Mar 7, 2026 | 5.3 | 20 | NO | NO |
CVE-2026-25123MEDIUM Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an arbitrary url and performs a server-side request to that UR | Feb 6, 2026 | 5.3 | 18 | NO | NO |
CVE-2026-32602MEDIUM Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnerable to a race condition that allows an attacker to create mu | Apr 6, 2026 | 4.2 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Homarr.
Media articles that mention a CVE ID that affects a product developed by Homarr — matched by CVE ID, not by vendor name.