Known Vulnerabilities for products from Calibre-web Project
Listed below are 18 of the newest known vulnerabilities associated with the vendor "Calibre-web Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-7714 json | Not Provided | 2026-05-04 | 2026-05-04 | |
| CVE-2023-2106 json | Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. | 9.8 - CRITICAL | 2023-04-15 | 2023-04-25 |
| CVE-2022-30765 json | Calibre-Web before 0.6.18 allows user table SQL Injection. | 9.8 - CRITICAL | 2022-05-16 | 2022-05-24 |
| CVE-2022-2525 json | Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. | 9.8 - CRITICAL | 2023-04-15 | 2023-04-24 |
| CVE-2022-0990 json | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | 9.1 - CRITICAL | 2022-04-04 | 2022-04-12 |
| CVE-2022-0939 json | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | 9.9 - CRITICAL | 2022-04-04 | 2022-04-11 |
| CVE-2022-0767 json | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. | 9.9 - CRITICAL | 2022-03-07 | 2022-03-14 |
| CVE-2022-0766 json | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. | 9.8 - CRITICAL | 2022-03-07 | 2022-03-11 |
| CVE-2022-0406 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 4.3 - MEDIUM | 2022-04-03 | 2022-04-09 |
| CVE-2022-0405 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 4.3 - MEDIUM | 2022-04-03 | 2022-04-11 |
| CVE-2022-0352 json | Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16. | 6.1 - MEDIUM | 2022-01-28 | 2022-03-15 |
| CVE-2022-0339 json | Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16. | 9.8 - CRITICAL | 2022-01-30 | 2022-03-17 |
| CVE-2022-0273 json | Improper Access Control in Pypi calibreweb prior to 0.6.16. | 6.5 - MEDIUM | 2022-01-30 | 2022-03-17 |
| CVE-2021-25965 json | In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user... | 8.8 - HIGH | 2021-11-16 | 2021-11-17 |
| CVE-2021-25964 json | In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has acc... | 5.4 - MEDIUM | 2021-10-04 | 2021-10-08 |
| CVE-2021-4171 json | calibre-web is vulnerable to Business Logic Errors | 9.8 - CRITICAL | 2022-01-17 | 2022-01-24 |
| CVE-2021-4170 json | calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | 5.4 - MEDIUM | 2022-01-16 | 2022-01-22 |
| CVE-2021-4164 json | calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) | 8.8 - HIGH | 2022-01-17 | 2022-01-22 |
| CVE-2020-12627 json | Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key. | 9.8 - CRITICAL | 2020-05-04 | 2021-07-21 |
Known software with vulnerabilities from Calibre-web Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Calibre-web Project | Calibre-web | 0.6.0 |