{"id":"CVE-2021-4170","aliases":["GHSA-wrp6-9w7f-3wxg","PYSEC-2026-620"],"title":"calibre-web is vulnerable to Cross-site Scripting","summary":"calibre-web is vulnerable to Cross-site Scripting","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","vendor":"calibreweb","product":"calibreweb","ecosystem":"pip","affected":["calibreweb < 0.6.15"],"patched":["calibreweb 0.6.15"],"published":"2022-01-21","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-wrp6-9w7f-3wxg","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-4170"},{"url":"https://github.com/janeczku/calibre-web/commit/7ad419dc8c12180e842a82118f4866ac3d074bc5"},{"url":"https://github.com/janeczku/calibre-web"},{"url":"https://huntr.dev/bounties/ff395101-e392-401d-ab4f-579c63fbf6a0"}],"tags":["osv","pip"],"epss":0.00809,"epssPercentile":0.55366,"ingestedAt":"2026-07-08T18:25:53.901Z","slug":"CVE-2021-4170","body":"## Overview\n\ncalibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\n\n## Affected packages\n\n- `calibreweb < 0.6.15`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `calibreweb 0.6.15`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}