Homarr

Homarr

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 06.04.2026 14:51:38
  • Zuletzt bearbeitet 09.04.2026 18:40:47

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login page. The application improperly trusts a URL parameter (callbackUrl), which is passed to redirect a...

  • EPSS 0.03%
  • Veröffentlicht 06.04.2026 14:42:37
  • Zuletzt bearbeitet 10.04.2026 18:00:42

Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnerable to a race condition that allows an attacker to create multiple user accounts from a single-use invite token. The registration ...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 07.03.2026 05:54:48
  • Zuletzt bearbeitet 10.03.2026 16:24:21

Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing unauthenticated users to retrieve a complete list of configured integrations. This metadata includes se...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 07.03.2026 05:54:32
  • Zuletzt bearbeitet 10.03.2026 16:24:46

Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability allows a remote attacker to force the Homarr server to perform arbitrary outbound HTTP requests. This can be used as an i...

  • EPSS 0.02%
  • Veröffentlicht 06.02.2026 21:19:40
  • Zuletzt bearbeitet 18.02.2026 18:08:19

Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an arbitrary url and performs a server-side request to that URL. This allows an unauthenticated attacker to trigger outbound HTTP re...

  • EPSS 0.15%
  • Veröffentlicht 17.12.2025 21:16:15
  • Zuletzt bearbeitet 30.01.2026 18:32:21

Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege escalation and getting access to groups of other users due to missing sanitization of inputs in ldap search query. The vulnerabilit...

  • EPSS 0.1%
  • Veröffentlicht 19.11.2025 18:44:09
  • Zuletzt bearbeitet 14.04.2026 15:42:45

Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a user's browser, with minimal or no user interaction required, due to the rendering of a malicious upload...

Warnung Medienbericht Exploit
  • EPSS 10.46%
  • Veröffentlicht 19.07.2025 00:00:00
  • Zuletzt bearbeitet 23.01.2026 18:33:09

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.