Skip to main content

Vendor/product archive

janeczku / calibre-web CVEs

Beta · best-effort

24 CVEs tagged to janeczku / calibre-web10 Critical, 2 High, 11 Medium, 1 Low, 0 Unrated.

CVE-2025-65858

Published Dec 2, 2025

A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payloa…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-3988

Published Nov 15, 2024

A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The vulnerability occurs when editing book properties, such as…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3987

Published Nov 15, 2024

An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerabi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3986

Published Nov 15, 2024

A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39123

Published Jul 19, 2024

In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string fun…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2525

Published Apr 15, 2023

Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-0990

Published Apr 4, 2022

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-0939

Published Apr 4, 2022

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-0767

Published Mar 7, 2022

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-0766

Published Mar 7, 2022

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-4170

Published Jan 16, 2022

calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25965

Published Nov 16, 2021

In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25964

Published Oct 4, 2021

In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript pa…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12627

Published May 4, 2020

Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1