Go Shiori is a lightweight, open-source bookmarking and web-clipping application that serves as a personal content management tool. The vendor's limited vulnerability footprint reflects the narrowly scoped nature of the product and its role as a self-hosted, standalone utility rather than a broad platform or library. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Go Shiori over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-61463HIGH Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attacker | Jul 13, 2026 | 8.8 | 38 | NO | NO |
CVE-2025-60538MEDIUM A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack. | Jan 9, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Go Shiori.
Media articles that mention a CVE ID that affects a product developed by Go Shiori — matched by CVE ID, not by vendor name.