Vulnerabilities (CVE)

Filtered by vendor Calibre-web Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0352 1 Calibre-web Project 1 Calibre-web 2022-02-14 4.3 MEDIUM 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16.
CVE-2022-0273 1 Calibre-web Project 1 Calibre-web 2022-02-14 4.0 MEDIUM 6.5 MEDIUM
Improper Access Control in Pypi calibreweb prior to 0.6.16.
CVE-2021-4170 1 Calibre-web Project 1 Calibre-web 2022-01-22 3.5 LOW 5.4 MEDIUM
calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-25964 1 Calibre-web Project 1 Calibre-web 2021-10-08 3.5 LOW 5.4 MEDIUM
In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered.