CVE-2025-65858Low▾ TwilightPoC availableCalibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 13.8 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.2%
1 GitHub repo
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.
calibreweb <= 0.6.25Refer to the advisory for the patched release.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-7404MediumCalibre Web and Autocaliweb have OS Command Injection vulnerability
CVE-2024-39123Medium· 5.4Calibre-Web Cross Site Scripting (XSS)
CVE-2025-6998HighCalibre Web and Autocaliweb have a ReDoS vulnerability
CVE-2021-4164High· 7.6calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4170Medium· 5.4calibre-web is vulnerable to Cross-site Scripting
CVE-2021-3988Medium· 6.1Cross-site Scripting (XSS) - DOM in janeczku/calibre-web