Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Calibre Web MEDIUM 6.1
CVE-2021-3988

A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The vulnerability occurs when ed…

Fix: 0.6.15+
Fix from $1,600 2024-11-15
Calibre Web MEDIUM 5.4
CVE-2024-39123EPSS 23%

In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization per…

Fix: after 0.6.21
Fix from $1,600 2024-07-19
Calibre Web CRITICAL 9.8
CVE-2023-2106

Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.

Fix: 0.6.20+
Fix from $2,300 2023-04-15
Calibre Web CRITICAL 9.8
CVE-2022-2525

Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.

Fix: 0.6.20+
Fix from $2,300 2023-04-15
Calibre Web CRITICAL 9.8
CVE-2022-30765

Calibre-Web before 0.6.18 allows user table SQL Injection.

Mitigation only
Fix from $2,300 2022-05-16
Calibre Web CRITICAL 9.1
CVE-2022-0990

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

Fix: 0.6.18+
Fix from $2,300 2022-04-04
Calibre Web CRITICAL 9.9
CVE-2022-0939

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

Fix: 0.6.18+
Fix from $2,300 2022-04-04
Calibre Web CRITICAL 9.9
CVE-2022-0767

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

Fix: 0.6.17+
Fix from $2,300 2022-03-07
Calibre Web CRITICAL 9.8
CVE-2022-0766

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

Fix: 0.6.17+
Fix from $2,300 2022-03-07
Calibre Web CRITICAL 9.8
CVE-2022-0339

Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.

Fix: 0.6.16+
Fix from $2,300 2022-01-30
Calibre Web MEDIUM 6.5
CVE-2022-0273

Improper Access Control in Pypi calibreweb prior to 0.6.16.

Fix: 0.6.16+
Fix from $1,600 2022-01-30
Calibre Web MEDIUM 6.1
CVE-2022-0352

Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16.

Fix: 0.6.16+
Fix from $1,600 2022-01-28
Calibre Web HIGH 8.8
CVE-2021-4164

calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 0.6.15+
Fix from $1,950 2022-01-17
Calibre Web CRITICAL 9.8
CVE-2021-4171

calibre-web is vulnerable to Business Logic Errors

Fix: 0.6.15+
Fix from $2,300 2022-01-17
Calibre Web MEDIUM 5.4
CVE-2021-4170

calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: 0.6.15+
Fix from $1,600 2022-01-16
Calibre Web HIGH 8.8
CVE-2021-25965

In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an …

Fix: after 0.6.13
Fix from $1,950 2021-11-16
Calibre Web MEDIUM 5.4
CVE-2021-25964

In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata informa…

Fix: 0.6.12+
Fix from $1,600 2021-10-04
Calibre Web CRITICAL 9.8
CVE-2020-12627

Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.

Patch available
Fix from $2,300 2020-05-04