Vendorsjaneczkucalibre-weball versions
Vulnerabilities

janeczku Calibre-Web

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2022-0939
Server-Side Request Forgery (SSRF) in janeczku/calibre-web
Published 2022-04-04 · Modified
9.9EPSS 0.011
CVE-2022-0767
Server-Side Request Forgery (SSRF) in janeczku/calibre-web
Published 2022-03-07 · Modified
9.9EPSS 0.010
CVE-2025-7404
Calibre Web 0.6.24 & Autocaliweb 0.7.0 - Blind C
Published 2025-07-24 · Analyzed
9.8EPSS 0.028
CVE-2021-4171
Business Logic Errors in janeczku/calibre-web
Published 2022-01-17 · Modified
9.8EPSS 0.014
CVE-2020-12627
Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.
Published 2020-05-04 · Modified
9.8EPSS 0.014
CVE-2022-0766
Server-Side Request Forgery (SSRF) in janeczku/calibre-web
Published 2022-03-07 · Modified
9.8EPSS 0.013
CVE-2022-30765
Calibre-Web before 0.6.18 allows user table SQL Injection.
Published 2022-05-16 · Modified
9.8EPSS 0.012
CVE-2022-0339
Server-Side Request Forgery (SSRF) in janeczku/calibre-web
Published 2022-01-30 · Modified
9.8EPSS 0.010
CVE-2022-2525
Improper Restriction of Excessive Authentication Attempts in janeczku/calibre-web
Published 2023-04-15 · Modified
9.8EPSS 0.008
CVE-2023-2106
Weak Password Requirements in janeczku/calibre-web
Published 2023-04-15 · Modified
9.8EPSS 0.007
CVE-2022-0990
Server-Side Request Forgery (SSRF) in janeczku/calibre-web
Published 2022-04-04 · Modified
9.3EPSS 0.013
CVE-2021-4164
Cross-Site Request Forgery (CSRF) in janeczku/calibre-web
Published 2022-01-17 · Modified
8.8EPSS 0.005
CVE-2021-25965
Calibre-web - Admin Account Takeover via Cross-Site Request Forgery (CSRF)
Published 2021-11-16 · Modified
8.8EPSS 0.005
CVE-2022-0352
Cross-site Scripting (XSS) - Reflected in janeczku/calibre-web
Published 2022-01-28 · Modified
8.5EPSS 0.009
CVE-2021-4170
Cross-site Scripting (XSS) - Stored in janeczku/calibre-web
Published 2022-01-16 · Modified
7.3EPSS 0.008
CVE-2022-0273
Improper Access Control in janeczku/calibre-web
Published 2022-01-30 · Modified
6.5EPSS 0.007
CVE-2021-3988
Cross-site Scripting (XSS) in janeczku/calibre-web
Published 2024-11-15 · Analyzed
6.1EPSS 0.004
CVE-2024-39123
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization.
Published 2024-07-19 · Analyzed
5.4EPSS 0.231
CVE-2021-25964
Stored Cross-Site Scripting (XSS) in Calibre-web via Description Field in Metadata
Published 2021-10-04 · Modified
5.4EPSS 0.005
CVE-2021-3987
Improper Access Control in janeczku/calibre-web
Published 2024-11-15 · Analyzed
5.4EPSS 0.003
CVE-2022-0405
Improper Access Control in janeczku/calibre-web
Published 2022-04-03 · Modified
4.3EPSS 0.008
CVE-2022-0406
Improper Authorization in janeczku/calibre-web
Published 2022-04-03 · Modified
4.3EPSS 0.007
CVE-2021-3986
Information Disclosure in janeczku/calibre-web
Published 2024-11-15 · Analyzed
4.3EPSS 0.004
CVE-2025-65858
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.
Published 2025-12-02 · Analyzed
3.5EPSS 0.002