All 4 CVE vulnerabilities found in Kavita, with AI-generated Chinese analysis, references, and POCs.
Vendor: Kareadita
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-47202 | Kavita: Pre-Auth Account Takeover CWE-287 | - | - | 2026-05-26 |
| CVE-2026-44776 | Kavita: IDOR in /api/Download/* CWE-639 | - | - | 2026-05-26 |
| CVE-2026-44775 | Kavita: No authentication at /api/Reader/image CWE-306 | - | - | 2026-05-26 |
| CVE-2024-39307 | Cross-Site Scripting (XSS) vulnerability via crafted ebooks in Kavita CWE-79 | 3.5 | Low | 2024-06-28 |
All 4 known CVE vulnerabilities affecting Kavita with full Chinese analysis, references, and POCs where available.