Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Homarr

First CVE: Jul 19, 2025Active for: 1 yearTotal CVEs: 8

Homarr is a dashboard and home-server management application with a concentrated vulnerability footprint centered on its single core product, where vulnerabilities skew toward serious outcomes with an elevated tendency toward confirmed in-the-wild exploitation. The recurring exposure reflects the application's web-facing and server-side integration role, clustering around input-validation weaknesses, server-side request forgery, embedded malicious code, sensitive information leakage, and cross-site scripting—the characteristic flaws of a centralized orchestration interface handling untrusted requests and managing downstream services. Defenders should treat this vendor's advisories as impactful to the home-server and automation community; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
12.5%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Homarr over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 19, 2025
12 months ago
Most Recent CVE
Apr 6, 2026
109 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-54313HIGH
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that
Jul 19, 20257.565YESNO
CVE-2026-33510HIGH
Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login page. The application improper
Apr 6, 20268.830NONO
CVE-2026-27796HIGH
Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing unauthenticated users to retrieve
Mar 7, 20267.525NONO
CVE-2025-67493CRITICAL
Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege escalation and getting access to groups of other users due to
Dec 17, 20259.025NONO
CVE-2025-64759MEDIUM
Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a user's browser, with minimal or no
Nov 19, 20256.122NONO
CVE-2026-27797MEDIUM
Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability allows a remote attacker to force the Homarr server
Mar 7, 20265.320NONO
CVE-2026-25123MEDIUM
Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an arbitrary url and performs a server-side request to that UR
Feb 6, 20265.318NONO
CVE-2026-32602MEDIUM
Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnerable to a race condition that allows an attacker to create mu
Apr 6, 20264.216NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
50%
38%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High2 (25.0%)
Unknown0 (0.0%)
User Interaction
None5 (62.5%)
Unknown0 (0.0%)
Required3 (37.5%)
Privileges Required
Low2 (25.0%)
High1 (12.5%)
None5 (62.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
1 CVE
12.5% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Homarr.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Homarr — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Homarr's Products

View all 2 CNAs →

Top CWEs