LinuxServer.io Heimdall < 2.7.3 contains a stored XSS caused by improper sanitization of the \"q\" parameter, letting remote attackers execute scripts, exploit requires crafted input.
id: CVE-2025-54597
info:
name: Heimdall Application Dashboard < 2.7.3 - Reflected XSS
author: 0
...