Janeczku maintains Calibre-Web, a web-based e-book management and serving application that, despite its narrow product focus, operates in environments where it often handles user authentication and content distribution. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate in web-application input-handling and access-control classes, including cross-site scripting, server-side request forgery, improper access control, cross-site request forgery, and authorization flaws that are characteristic of web-facing applications. The recurring pattern reflects the intersection of user input processing, cross-domain requests, and privilege boundaries inherent to a web-based library interface. Defenders deploying this application should prioritize security updates and restrict network exposure; current severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Janeczku over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0767CRITICAL Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. | Mar 7, 2022 | 9.9 | 31 | NO | NO |
CVE-2021-4171CRITICAL calibre-web is vulnerable to Business Logic Errors | Jan 17, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-2106CRITICAL Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. | Apr 15, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-30765CRITICAL Calibre-Web before 0.6.18 allows user table SQL Injection. | May 16, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-0939CRITICAL Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | Apr 4, 2022 | 9.9 | 30 | NO | NO |
CVE-2022-0766CRITICAL Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. | Mar 7, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-0339CRITICAL Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16. | Jan 30, 2022 | 9.8 | 30 | NO | NO |
CVE-2025-7404CRITICAL Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This issue af | Jul 24, 2025 | 9.8 | 29 | NO | NO |
CVE-2022-0990CRITICAL Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | Apr 4, 2022 | 9.1 | 29 | NO | NO |
CVE-2021-4164HIGH calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) | Jan 17, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Janeczku.
Media articles that mention a CVE ID that affects a product developed by Janeczku — matched by CVE ID, not by vendor name.