calibreweb
:books: Web app for browsing, reading and downloading eBooks stored in a Calibre database
Activity
- Latest release
- 1mo ago
- Total releases
- 16
- Cadence
- ~4 months
- Last 12 months
- 2
Reach
- Stars
- 17.9k
Details
- License
- unknown
- First release
- May 22, 2021
| Version | Released | |
|---|---|---|
0.6.27
patch
|
0.6.27
patch
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
0.6.26
patch
|
0.6.26
patch
Dependencies (57)
+ 49 more
Changelog
Compare changes
|
|
0.6.25
patch
1 CVE
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev |
0.6.25
patch
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
0.6.24
patch
3 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev |
0.6.24
patch
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
0.6.23
patch
3 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev |
0.6.23
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
0.6.22
patch
3 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev |
0.6.22
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
0.6.21
patch
4 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39123
PYSEC-2026-1230
GHSA-j22r-3rf3-cv25
Jul 07, 2026
Calibre-Web Cross Site Scripting (XSS)
Low
Network
Low
Low
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
References Updated Jul 07, 2026 · Source: OSV.dev |
0.6.21
patch
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
0.6.20
patch
4 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39123
PYSEC-2026-1230
GHSA-j22r-3rf3-cv25
Jul 07, 2026
Calibre-Web Cross Site Scripting (XSS)
Low
Network
Low
Low
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
References Updated Jul 07, 2026 · Source: OSV.dev |
0.6.20
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.6.19
patch
6 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39123
PYSEC-2026-1230
GHSA-j22r-3rf3-cv25
Jul 07, 2026
Calibre-Web Cross Site Scripting (XSS)
Low
Network
Low
Low
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-2525
PYSEC-2026-1231
GHSA-jg8w-wgx2-g7q4
Jul 07, 2026
Improper Restriction of Excessive Authentication Attempts in calibreweb Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-2106
PYSEC-2026-1233
GHSA-mhmp-m6g7-7c24
Jul 07, 2026
Weak Password Requirements in calibreweb
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References
Updated Jul 07, 2026 · Source: OSV.dev |
0.6.19
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
0.6.18
patch
6 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39123
PYSEC-2026-1230
GHSA-j22r-3rf3-cv25
Jul 07, 2026
Calibre-Web Cross Site Scripting (XSS)
Low
Network
Low
Low
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-2525
PYSEC-2026-1231
GHSA-jg8w-wgx2-g7q4
Jul 07, 2026
Improper Restriction of Excessive Authentication Attempts in calibreweb Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-2106
PYSEC-2026-1233
GHSA-mhmp-m6g7-7c24
Jul 07, 2026
Weak Password Requirements in calibreweb
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References
Updated Jul 07, 2026 · Source: OSV.dev |
0.6.18
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
0.6.17
patch
7 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39123
PYSEC-2026-1230
GHSA-j22r-3rf3-cv25
Jul 07, 2026
Calibre-Web Cross Site Scripting (XSS)
Low
Network
Low
Low
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-2525
PYSEC-2026-1231
GHSA-jg8w-wgx2-g7q4
Jul 07, 2026
Improper Restriction of Excessive Authentication Attempts in calibreweb Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-2106
PYSEC-2026-1233
GHSA-mhmp-m6g7-7c24
Jul 07, 2026
Weak Password Requirements in calibreweb
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-30765
PYSEC-2026-305
GHSA-8ppf-x4gr-2x7g
Jun 29, 2026
SQL injection in calibreweb
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Calibre-Web before 0.6.18 allows user table SQL Injection. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
Fixed in
0.6.18
References Updated Jul 01, 2026 · Source: OSV.dev |
0.6.17
patch
Dependencies (45)
+ 37 more
Changelog
Compare changes
|
|
0.6.16
patch
9 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39123
PYSEC-2026-1230
GHSA-j22r-3rf3-cv25
Jul 07, 2026
Calibre-Web Cross Site Scripting (XSS)
Low
Network
Low
Low
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-2525
PYSEC-2026-1231
GHSA-jg8w-wgx2-g7q4
Jul 07, 2026
Improper Restriction of Excessive Authentication Attempts in calibreweb Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-2106
PYSEC-2026-1233
GHSA-mhmp-m6g7-7c24
Jul 07, 2026
Weak Password Requirements in calibreweb
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-30765
PYSEC-2026-305
GHSA-8ppf-x4gr-2x7g
Jun 29, 2026
SQL injection in calibreweb
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Calibre-Web before 0.6.18 allows user table SQL Injection. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
Fixed in
0.6.18
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0767
PYSEC-2026-306
GHSA-h65g-jfqg-2w6m
Jun 29, 2026
Server-Side Request Forgery in calibreweb
9.9
/ 10
Critical
Network
Low
None
None
Changed
Low
Low
High
calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is a result of incomplete SSRF protection that can be bypassed via an HTTP redirect. An HTTP server set up to respond with a 302 redirect may redirect a request to Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
Fixed in
0.6.17
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0766
PYSEC-2026-304
GHSA-2647-c639-qv2j
Jun 29, 2026
Server-Side Request Forgery in calibreweb
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is due to an incomplete fix for CVE-2022-0339. The blacklist does not check for Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
Fixed in
0.6.17
References
Updated Jul 01, 2026 · Source: OSV.dev |
0.6.16
patch
Dependencies (41)
+ 33 more
Changelog
Compare changes
|
|
0.6.15
patch
12 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39123
PYSEC-2026-1230
GHSA-j22r-3rf3-cv25
Jul 07, 2026
Calibre-Web Cross Site Scripting (XSS)
Low
Network
Low
Low
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-2525
PYSEC-2026-1231
GHSA-jg8w-wgx2-g7q4
Jul 07, 2026
Improper Restriction of Excessive Authentication Attempts in calibreweb Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-2106
PYSEC-2026-1233
GHSA-mhmp-m6g7-7c24
Jul 07, 2026
Weak Password Requirements in calibreweb
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-30765
PYSEC-2026-305
GHSA-8ppf-x4gr-2x7g
Jun 29, 2026
SQL injection in calibreweb
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Calibre-Web before 0.6.18 allows user table SQL Injection. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
Fixed in
0.6.18
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0767
PYSEC-2026-306
GHSA-h65g-jfqg-2w6m
Jun 29, 2026
Server-Side Request Forgery in calibreweb
9.9
/ 10
Critical
Network
Low
None
None
Changed
Low
Low
High
calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is a result of incomplete SSRF protection that can be bypassed via an HTTP redirect. An HTTP server set up to respond with a 302 redirect may redirect a request to Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
Fixed in
0.6.17
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0766
PYSEC-2026-304
GHSA-2647-c639-qv2j
Jun 29, 2026
Server-Side Request Forgery in calibreweb
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is due to an incomplete fix for CVE-2022-0339. The blacklist does not check for Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
Fixed in
0.6.17
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0339
GHSA-4w8p-x6g8-fv64
PYSEC-2022-23
Feb 01, 2022
Server-Side Request Forgery in calibreweb
Medium
Network
Low
None
calibreweb prior to version 0.6.16 contains a Server-Side Request Forgery (SSRF) vulnerability. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
Fixed in
0.6.16
References
Updated Nov 19, 2024 · Source: OSV.dev
CVE-2022-0273
GHSA-vgmw-9cww-qq99
PYSEC-2022-22
Jan 31, 2022
Incorrect Authorization in calibreweb
High
Network
Low
Low
None
calibreweb prior to version 0.6.16 contains an Incorrect Authorization vulnerability. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
Fixed in
0.6.16
References
Updated Nov 27, 2024 · Source: OSV.dev
CVE-2022-0352
GHSA-h56g-v4vp-q9q6
PYSEC-2022-18
Jan 29, 2022
Cross-site Scripting in calibreweb
Medium
Network
Low
None
calibreweb prior to version 0.6.16 contains a cross-site scripting vulnerability. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
Fixed in
0.6.16
References
Updated Nov 19, 2024 · Source: OSV.dev |
0.6.15
patch
Dependencies (41)
+ 33 more
Changelog
Compare changes
|
|
0.6.14
patch
18 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3986
PYSEC-2026-1232
GHSA-m982-h4f8-g4hf
Jul 07, 2026
Generation of Error Message Containing Sensitive Information in janeczku/calibre-web
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221, where the name of the shelf is exposed in an error message when a user attempts to remove a book from a shelf they do not own. This vulnerability discloses private information and affects all versions prior to the fix. Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3988
PYSEC-2026-1236
GHSA-r735-9gc6-2hvq
Jul 07, 2026
Cross-site Scripting (XSS) - DOM in janeczku/calibre-web
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3987
PYSEC-2026-1229
GHSA-fj5v-w2jp-wqvj
Jul 07, 2026
Improper Access Control in janeczku/calibre-web
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39123
PYSEC-2026-1230
GHSA-j22r-3rf3-cv25
Jul 07, 2026
Calibre-Web Cross Site Scripting (XSS)
Low
Network
Low
Low
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-2525
PYSEC-2026-1231
GHSA-jg8w-wgx2-g7q4
Jul 07, 2026
Improper Restriction of Excessive Authentication Attempts in calibreweb Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-2106
PYSEC-2026-1233
GHSA-mhmp-m6g7-7c24
Jul 07, 2026
Weak Password Requirements in calibreweb
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-4170
PYSEC-2026-620
GHSA-wrp6-9w7f-3wxg
Jul 02, 2026
calibre-web is vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2021-4164
PYSEC-2026-621
GHSA-wxr6-29pv-ch68
Jul 02, 2026
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
7.6
/ 10
High
Network
Low
None
Required
Unchanged
Low
Low
High
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2021-4171
PYSEC-2026-307
GHSA-xp7p-3gx7-j6wx
Jun 29, 2026
calibre-web is vulnerable to Business Logic Errors
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
calibre-web is vulnerable to Business Logic Errors Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-30765
PYSEC-2026-305
GHSA-8ppf-x4gr-2x7g
Jun 29, 2026
SQL injection in calibreweb
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Calibre-Web before 0.6.18 allows user table SQL Injection. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
Fixed in
0.6.18
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0767
PYSEC-2026-306
GHSA-h65g-jfqg-2w6m
Jun 29, 2026
Server-Side Request Forgery in calibreweb
9.9
/ 10
Critical
Network
Low
None
None
Changed
Low
Low
High
calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is a result of incomplete SSRF protection that can be bypassed via an HTTP redirect. An HTTP server set up to respond with a 302 redirect may redirect a request to Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
Fixed in
0.6.17
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0766
PYSEC-2026-304
GHSA-2647-c639-qv2j
Jun 29, 2026
Server-Side Request Forgery in calibreweb
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is due to an incomplete fix for CVE-2022-0339. The blacklist does not check for Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
Fixed in
0.6.17
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0339
GHSA-4w8p-x6g8-fv64
PYSEC-2022-23
Feb 01, 2022
Server-Side Request Forgery in calibreweb
Medium
Network
Low
None
calibreweb prior to version 0.6.16 contains a Server-Side Request Forgery (SSRF) vulnerability. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
Fixed in
0.6.16
References
Updated Nov 19, 2024 · Source: OSV.dev
CVE-2022-0273
GHSA-vgmw-9cww-qq99
PYSEC-2022-22
Jan 31, 2022
Incorrect Authorization in calibreweb
High
Network
Low
Low
None
calibreweb prior to version 0.6.16 contains an Incorrect Authorization vulnerability. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
Fixed in
0.6.16
References
Updated Nov 27, 2024 · Source: OSV.dev
CVE-2022-0352
GHSA-h56g-v4vp-q9q6
PYSEC-2022-18
Jan 29, 2022
Cross-site Scripting in calibreweb
Medium
Network
Low
None
calibreweb prior to version 0.6.16 contains a cross-site scripting vulnerability. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
Fixed in
0.6.16
References
Updated Nov 19, 2024 · Source: OSV.dev |
0.6.14
patch
Dependencies (40)
+ 32 more
Changelog
Compare changes
|
|
0.6.13
patch
18 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3986
PYSEC-2026-1232
GHSA-m982-h4f8-g4hf
Jul 07, 2026
Generation of Error Message Containing Sensitive Information in janeczku/calibre-web
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221, where the name of the shelf is exposed in an error message when a user attempts to remove a book from a shelf they do not own. This vulnerability discloses private information and affects all versions prior to the fix. Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3988
PYSEC-2026-1236
GHSA-r735-9gc6-2hvq
Jul 07, 2026
Cross-site Scripting (XSS) - DOM in janeczku/calibre-web
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3987
PYSEC-2026-1229
GHSA-fj5v-w2jp-wqvj
Jul 07, 2026
Improper Access Control in janeczku/calibre-web
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39123
PYSEC-2026-1230
GHSA-j22r-3rf3-cv25
Jul 07, 2026
Calibre-Web Cross Site Scripting (XSS)
Low
Network
Low
Low
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-2525
PYSEC-2026-1231
GHSA-jg8w-wgx2-g7q4
Jul 07, 2026
Improper Restriction of Excessive Authentication Attempts in calibreweb Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-2106
PYSEC-2026-1233
GHSA-mhmp-m6g7-7c24
Jul 07, 2026
Weak Password Requirements in calibreweb
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-4170
PYSEC-2026-620
GHSA-wrp6-9w7f-3wxg
Jul 02, 2026
calibre-web is vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2021-4164
PYSEC-2026-621
GHSA-wxr6-29pv-ch68
Jul 02, 2026
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
7.6
/ 10
High
Network
Low
None
Required
Unchanged
Low
Low
High
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2021-4171
PYSEC-2026-307
GHSA-xp7p-3gx7-j6wx
Jun 29, 2026
calibre-web is vulnerable to Business Logic Errors
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
calibre-web is vulnerable to Business Logic Errors Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-30765
PYSEC-2026-305
GHSA-8ppf-x4gr-2x7g
Jun 29, 2026
SQL injection in calibreweb
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Calibre-Web before 0.6.18 allows user table SQL Injection. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
Fixed in
0.6.18
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0767
PYSEC-2026-306
GHSA-h65g-jfqg-2w6m
Jun 29, 2026
Server-Side Request Forgery in calibreweb
9.9
/ 10
Critical
Network
Low
None
None
Changed
Low
Low
High
calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is a result of incomplete SSRF protection that can be bypassed via an HTTP redirect. An HTTP server set up to respond with a 302 redirect may redirect a request to Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
Fixed in
0.6.17
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0766
PYSEC-2026-304
GHSA-2647-c639-qv2j
Jun 29, 2026
Server-Side Request Forgery in calibreweb
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is due to an incomplete fix for CVE-2022-0339. The blacklist does not check for Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
Fixed in
0.6.17
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0339
GHSA-4w8p-x6g8-fv64
PYSEC-2022-23
Feb 01, 2022
Server-Side Request Forgery in calibreweb
Medium
Network
Low
None
calibreweb prior to version 0.6.16 contains a Server-Side Request Forgery (SSRF) vulnerability. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
Fixed in
0.6.16
References
Updated Nov 19, 2024 · Source: OSV.dev
CVE-2022-0273
GHSA-vgmw-9cww-qq99
PYSEC-2022-22
Jan 31, 2022
Incorrect Authorization in calibreweb
High
Network
Low
Low
None
calibreweb prior to version 0.6.16 contains an Incorrect Authorization vulnerability. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
Fixed in
0.6.16
References
Updated Nov 27, 2024 · Source: OSV.dev
CVE-2022-0352
GHSA-h56g-v4vp-q9q6
PYSEC-2022-18
Jan 29, 2022
Cross-site Scripting in calibreweb
Medium
Network
Low
None
calibreweb prior to version 0.6.16 contains a cross-site scripting vulnerability. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
Fixed in
0.6.16
References
Updated Nov 19, 2024 · Source: OSV.dev |
0.6.13
patch
Dependencies (39)
+ 31 more
Changelog
Compare changes
|
|
0.6.12
initial
18 CVEs
CVE-2025-65858
PYSEC-2026-1234
GHSA-pc5g-j9j7-p4q3
Jul 07, 2026
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
Network
Low
High
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 2 more Show less
0.6.24
0.6.25
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6998
PYSEC-2026-1228
GHSA-2g7m-ph9x-7q7m
Jul 07, 2026
Calibre Web and Autocaliweb have a ReDoS vulnerability
High
Network
Low
None
None
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7404
PYSEC-2026-1235
GHSA-qc4j-v7h6-xr5h
Jul 07, 2026
Calibre Web and Autocaliweb have OS Command Injection vulnerability
High
Network
Low
High
None
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
0.6.22
0.6.23
+ 1 more Show less
0.6.24
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3986
PYSEC-2026-1232
GHSA-m982-h4f8-g4hf
Jul 07, 2026
Generation of Error Message Containing Sensitive Information in janeczku/calibre-web
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to other users. This issue occurs in the file shelf.py at line 221, where the name of the shelf is exposed in an error message when a user attempts to remove a book from a shelf they do not own. This vulnerability discloses private information and affects all versions prior to the fix. Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3988
PYSEC-2026-1236
GHSA-r735-9gc6-2hvq
Jul 07, 2026
Cross-site Scripting (XSS) - DOM in janeczku/calibre-web
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-3987
PYSEC-2026-1229
GHSA-fj5v-w2jp-wqvj
Jul 07, 2026
Improper Access Control in janeczku/calibre-web
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39123
PYSEC-2026-1230
GHSA-j22r-3rf3-cv25
Jul 07, 2026
Calibre-Web Cross Site Scripting (XSS)
Low
Network
Low
Low
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
0.6.20
0.6.21
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2022-2525
PYSEC-2026-1231
GHSA-jg8w-wgx2-g7q4
Jul 07, 2026
Improper Restriction of Excessive Authentication Attempts in calibreweb Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-2106
PYSEC-2026-1233
GHSA-mhmp-m6g7-7c24
Jul 07, 2026
Weak Password Requirements in calibreweb
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
0.6.18
0.6.19
Fixed in
0.6.20
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2021-4170
PYSEC-2026-620
GHSA-wrp6-9w7f-3wxg
Jul 02, 2026
calibre-web is vulnerable to Cross-site Scripting
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2021-4164
PYSEC-2026-621
GHSA-wxr6-29pv-ch68
Jul 02, 2026
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
7.6
/ 10
High
Network
Low
None
Required
Unchanged
Low
Low
High
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 06, 2026 · Source: OSV.dev
CVE-2021-4171
PYSEC-2026-307
GHSA-xp7p-3gx7-j6wx
Jun 29, 2026
calibre-web is vulnerable to Business Logic Errors
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
calibre-web is vulnerable to Business Logic Errors Affected versions
0.6.12
0.6.13
0.6.14
Fixed in
0.6.15
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-30765
PYSEC-2026-305
GHSA-8ppf-x4gr-2x7g
Jun 29, 2026
SQL injection in calibreweb
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Calibre-Web before 0.6.18 allows user table SQL Injection. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
0.6.17
Fixed in
0.6.18
References Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0767
PYSEC-2026-306
GHSA-h65g-jfqg-2w6m
Jun 29, 2026
Server-Side Request Forgery in calibreweb
9.9
/ 10
Critical
Network
Low
None
None
Changed
Low
Low
High
calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is a result of incomplete SSRF protection that can be bypassed via an HTTP redirect. An HTTP server set up to respond with a 302 redirect may redirect a request to Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
Fixed in
0.6.17
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0766
PYSEC-2026-304
GHSA-2647-c639-qv2j
Jun 29, 2026
Server-Side Request Forgery in calibreweb
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
calibreweb prior to version 0.6.17 is vulnerable to server-side request forgery (SSRF). This is due to an incomplete fix for CVE-2022-0339. The blacklist does not check for Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
0.6.16
Fixed in
0.6.17
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2022-0339
GHSA-4w8p-x6g8-fv64
PYSEC-2022-23
Feb 01, 2022
Server-Side Request Forgery in calibreweb
Medium
Network
Low
None
calibreweb prior to version 0.6.16 contains a Server-Side Request Forgery (SSRF) vulnerability. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
Fixed in
0.6.16
References
Updated Nov 19, 2024 · Source: OSV.dev
CVE-2022-0273
GHSA-vgmw-9cww-qq99
PYSEC-2022-22
Jan 31, 2022
Incorrect Authorization in calibreweb
High
Network
Low
Low
None
calibreweb prior to version 0.6.16 contains an Incorrect Authorization vulnerability. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
Fixed in
0.6.16
References
Updated Nov 27, 2024 · Source: OSV.dev
CVE-2022-0352
GHSA-h56g-v4vp-q9q6
PYSEC-2022-18
Jan 29, 2022
Cross-site Scripting in calibreweb
Medium
Network
Low
None
calibreweb prior to version 0.6.16 contains a cross-site scripting vulnerability. Affected versions
0.6.12
0.6.13
0.6.14
0.6.15
Fixed in
0.6.16
References
Updated Nov 19, 2024 · Source: OSV.dev |