Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 14 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Homarr
Homarr homarr |
|
| CPEs | cpe:2.3:a:homarr:homarr:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Homarr
Homarr homarr |
Fri, 21 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Homarr-labs
Homarr-labs homarr |
|
| Vendors & Products |
Homarr-labs
Homarr-labs homarr |
Wed, 19 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Nov 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a user's browser, with minimal or no user interaction required, due to the rendering of a malicious uploaded SVG file. This could be abused to add an attacker's account to the "credentials-admin" group, giving them full administrative access, if a user logged in as an administrator was to view the page which renders or redirects to the SVG. This issue has been patched in version 1.43.3. | |
| Title | Homarr is Vulnerable to Stored Cross-Site Scripting (XSS) and Possible Privilege Escalation via Malicious SVG Upload | |
| Weaknesses | CWE-20 CWE-434 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-19T21:14:41.116Z
Reserved: 2025-11-10T22:29:34.875Z
Link: CVE-2025-64759
Updated: 2025-11-19T21:14:37.443Z
Status : Analyzed
Published: 2025-11-19T19:15:49.963
Modified: 2026-04-14T15:42:45.563
Link: CVE-2025-64759
No data.
OpenCVE Enrichment
Updated: 2025-11-21T09:16:13Z