Sysadminsmedia's vulnerability footprint centers on its Homebox self-hosted application, with the durable signal concentrated in web-layer input handling and access-control issues including cross-site scripting, brute-force exposure, permission assignment flaws, and server-side request forgery. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sysadminsmedia over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40196HIGH HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being | Apr 17, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-27981HIGH HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the clie | Mar 3, 2026 | 7.4 | 25 | NO | NO |
CVE-2026-26272MEDIUM HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The | Mar 3, 2026 | 5.4 | 21 | NO | NO |
CVE-2026-27600MEDIUM HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application | Mar 3, 2026 | 4.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sysadminsmedia.
Media articles that mention a CVE ID that affects a product developed by Sysadminsmedia — matched by CVE ID, not by vendor name.