Skip to content

Latest commit

Β 

History

History

CVE-2025-XXXXX

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
Β 
Β 
Β 
Β 

πŸ™…πŸ» CVE-2025-XXXXX

Product CWE CWE CAPEC

πŸ“‹ Description

Homarr after v0.11.4 and before v0.15.8 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the iFrame widget that can be exploited using maliciously crafted hyperlinks.

🩹 Patch

The vulnerability was fixed in Pull Request #2215. More vulnerabilities were fixed in the same PR.

PR #2215

🐳 Vulnerable Lab

---
services:
  cve-2025-xxxxx:
    container_name: "homarr"
    image: "ghcr.io/ajnart/homarr:0.15.7"
    restart: "unless-stopped"
    ports: ["80:7575"]
...

βš›οΈ Nuclei Template

-- NOT AVAILABLE --

πŸ”— References