CVE-2021-3988Medium· 6.1▾ SunlitCross-site Scripting (XSS) - DOM in janeczku/calibre-web
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.4%
A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file edit_books.js. The vulnerability occurs when editing book properties, such as uploading a cover or a format. The affected code directly inserts user input into the DOM without proper sanitization, allowing attackers to execute arbitrary JavaScript code. This can lead to various attacks, including stealing cookies. The issue is present in the code handling the #btn-upload-cover change event.
calibreweb < 0.6.15Upgrade to a patched release:
calibreweb 0.6.15Connected by shared product, vendor, weakness, or advisory.
CVE-2021-4170Medium· 5.4calibre-web is vulnerable to Cross-site Scripting
CVE-2021-4164High· 7.6calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2025-7404MediumCalibre Web and Autocaliweb have OS Command Injection vulnerability
CVE-2025-65858LowCalibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
CVE-2023-2106High· 7.3Weak Password Requirements in calibreweb
CVE-2021-3986Medium· 4.3Generation of Error Message Containing Sensitive Information in janeczku/calibre-web