Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

janeczku/calibre-web — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in janeczku/calibre-web, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for the janeczku/calibre-web product, which is a web application for managing the Calibre e-book library, categorized primarily under web application injection weaknesses. It collects data on security flaws affecting this specific software package, covering reports from the time of the initial release through the most recent advisory. Visitors can use this aggregation to track the security posture of the janeczku/calibre-web project, understand common weakness classes such as cross-site scripting or server-side template injection, and review the historical record of identified defects. The collection supports security teams in auditing dependencies and prioritizing patches based on the severity and impact of each reported issue. By centralizing these findings, the page serves as a reference for developers and system administrators maintaining Calibre-based web interfaces. The information provided focuses on the technical nature of the vulnerabilities, the affected components, and the recommended remediation steps, enabling users to assess risk exposure and verify that their deployments have addressed known defects.

Vendor: janeczku

CVE ID Title CVSS Severity Published
CVE-2021-3988 Cross-site Scripting (XSS) in janeczku/calibre-web CWE-79 6.1AI Medium AI 2024-11-15
CVE-2021-3987 Improper Access Control in janeczku/calibre-web CWE-284 4.3AI Medium AI 2024-11-15
CVE-2021-3986 Information Disclosure in janeczku/calibre-web CWE-209 4.3AI Medium AI 2024-11-15
CVE-2022-2525 Improper Restriction of Excessive Authentication Attempts in janeczku/calibre-web CWE-307 9.1 - 2023-04-15
CVE-2023-2106 Weak Password Requirements in janeczku/calibre-web CWE-521 9.8 - 2023-04-15
CVE-2022-0990 Server-Side Request Forgery (SSRF) in janeczku/calibre-web CWE-918 9.4 - 2022-04-04
CVE-2022-0939 Server-Side Request Forgery (SSRF) in janeczku/calibre-web CWE-918 9.4 - 2022-04-04
CVE-2022-0406 Improper Authorization in janeczku/calibre-web CWE-285 5.4 - 2022-04-03
CVE-2022-0405 Improper Access Control in janeczku/calibre-web CWE-284 5.4 - 2022-04-03
CVE-2022-0766 Server-Side Request Forgery (SSRF) in janeczku/calibre-web CWE-918 9.4 - 2022-03-07
CVE-2022-0767 Server-Side Request Forgery (SSRF) in janeczku/calibre-web CWE-918 9.4 - 2022-03-07
CVE-2022-0273 Improper Access Control in janeczku/calibre-web CWE-284 6.5 - 2022-01-30
CVE-2022-0339 Server-Side Request Forgery (SSRF) in janeczku/calibre-web CWE-918 9.1 - 2022-01-30
CVE-2022-0352 Cross-site Scripting (XSS) - Reflected in janeczku/calibre-web CWE-79 6.1 - 2022-01-28
CVE-2021-4164 Cross-Site Request Forgery (CSRF) in janeczku/calibre-web CWE-352 8.1 - 2022-01-17
CVE-2021-4171 Business Logic Errors in janeczku/calibre-web CWE-840 8.2 - 2022-01-17
CVE-2021-4170 Cross-site Scripting (XSS) - Stored in janeczku/calibre-web CWE-79 6.1 - 2022-01-16

All 17 known CVE vulnerabilities affecting janeczku/calibre-web with full Chinese analysis, references, and POCs where available.