Joinbookwyrm develops a social book-cataloging and reading application that sits within the broader federated social network ecosystem, and its tracked vulnerabilities center on authentication and input-handling issues including authentication bypasses, improper authentication logic, cross-site scripting, brute-force exposure, and server-side request forgery. These weakness patterns reflect the challenges of securing a web application that bridges user authentication, content rendering, and external network interaction; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joinbookwyrm over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2651CRITICAL Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5. | Aug 4, 2022 | 9.8 | 48 | NO | YES |
CVE-2022-35925CRITICAL BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentication views which allows brute-force attacks. This issue has | Aug 2, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-23644HIGH BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable to a server-side request forgery | Feb 16, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-35953MEDIUM BookWyrm is a social network for tracking your reading, talking about books, writing reviews, and discovering what to read next. Some links in BookWyrm may be vulnerable to tabnabb | Aug 12, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-31136MEDIUM Bookwyrm is an open source social reading and reviewing program. Versions of Bookwyrm prior to 0.4.1 did not properly sanitize html being rendered to users. Unprivileged users are | Jul 7, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joinbookwyrm.
Media articles that mention a CVE ID that affects a product developed by Joinbookwyrm — matched by CVE ID, not by vendor name.