CVE-2022-47968: Linuxserver Heimdall Application Dashboard
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page.
Affected products
- Linuxserver Heimdall Application Dashboard: up to and including 2.5.4
Published 2022-12-27. Last modified 2026-06-17.