VulnSea

Reader vulnerabilities

CVEs whose affected-version data names the Reader package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-18312Medium· 6.1
today

Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping

Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping. The application interpolates untrusted values directly into URL strings and inserts them into the DOM via …

▾ SunlitReadwise · Readervia NVD
CVE-2026-18320Medium· 6.1
today

Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule

Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule. This configuration fails to remove script-capable attributes such as event handlers (e.…

▾ SunlitReadwise · Readervia NVD
CVE-2026-18311Medium· 6.1
today

Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata

Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as the author meta tag are inserted into a WebVie…

▾ SunlitReadwise · Readervia NVD
CVE-2026-85699High· 7.5PoC
3w ago

jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops

jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal…

▾ Midnightjina-ai · readerEPSS 0.48%via NVD
CVE-2026-82638High· 7.5PoC
3w ago

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery

jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresse…

▾ Midnightjina-ai · readerEPSS 0.50%via NVD
Reader vulnerabilities (CVEs) · VulnSea