Readwise has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.1 (medium). The most common weakness class is CWE-79 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-18320Medium· 6.1Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule34CVE-2026-18312Medium· 6.1Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping34CVE-2026-18311Medium· 6.1Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata34
Readwise vulnerabilities
CVEs affecting Readwise, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-18312Medium· 6.1Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping
Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping. The application interpolates untrusted values directly into URL strings and inserts them into the DOM via …
CVE-2026-18320Medium· 6.1Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule
Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule. This configuration fails to remove script-capable attributes such as event handlers (e.…
CVE-2026-18311Medium· 6.1Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata
Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as the author meta tag are inserted into a WebVie…