Bookreen operates a focused web application with a modest vulnerability footprint centered on input-handling and file-upload defenses, including incomplete validation of user-supplied inputs and unrestricted acceptance of dangerous file types. Treat this as a compact vendor profile rather than a broad risk trend; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bookreen over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3374CRITICAL Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation.
This issue affects Bookreen: before 3.0.0. | Sep 5, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-3375HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Unisign Bookreen allows OS Command Injection.
This issue affects Bookreen: before 3.0.0. | Sep 5, 2023 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bookreen.
Media articles that mention a CVE ID that affects a product developed by Bookreen — matched by CVE ID, not by vendor name.