Calibre-web Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    2
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-65858

    A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.

    Last Modified: Dec 23, 2025
    Published: Dec 02, 2025

    CVE-2021-3987

    Improper Access Control in janeczku/calibre-web

    Last Modified: Nov 19, 2024
    Published: Nov 15, 2024

    CVE-2021-3986

    Information Disclosure in janeczku/calibre-web

    Last Modified: Nov 19, 2024
    Published: Nov 15, 2024
    Items Per Page
    Calibre-Web_Project Vulnerabilities & Security CVEs | CVE-DB