Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/khanhduy155/calibre-web

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-7709 is a medium severity vulnerability in janeczku Calibre-Web up to version 0.6.26. It involves improper authorization due to manipulation of the user_id argument in the generate_auth_token function within cps/kobo_auth.py. The vulnerability can be exploited remotely without user interaction. Although an exploit is publicly available, there is no vendor response or official patch as of the publication date.

Join the discussion
CVE-2025-65858: n/aCVE-2025-65858
0

CVE-2025-65858 is a stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 that allows attackers with user creation privileges to inject malicious JavaScript into the username field. This payload is stored unsanitized and executed when the /ajax/listusers endpoint is accessed, potentially leading to limited confidentiality and integrity impacts. The vulnerability requires authenticated access and user interaction to trigger. Although the CVSS score is low (3.5), the flaw could be leveraged in targeted attacks within environments using Calibre-Web. No known exploits are currently reported in the wild, and no patches have been published yet. European organizations using Calibre-Web should be aware of this vulnerability and implement mitigations to prevent exploitation. Countries with higher adoption of Calibre-Web or with strategic interest in digital libraries and document management may be more affected.

Join the discussion
CVE-2024-39123: n/aCVE-2024-39123
0

In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:github/khanhduy155/calibre-web
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses