Linuxserver maintains containerized application deployments including the Heimdall application dashboard, which serves as a landing-page and service-management interface for self-hosted environments. Its vulnerability profile centers on web application input-handling and output-encoding weaknesses including cross-site scripting, open redirects, and injection-class flaws that are characteristic of client-facing dashboard and proxy-oriented software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linuxserver over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50578CRITICAL LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote | Jul 30, 2025 | 9.8 | 45 | NO | YES |
CVE-2025-54597MEDIUM LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter. | Jul 27, 2025 | 6.1 | 33 | NO | YES |
CVE-2022-47968MEDIUM Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Applicat | Dec 27, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linuxserver.
Media articles that mention a CVE ID that affects a product developed by Linuxserver — matched by CVE ID, not by vendor name.