Kavita is a focused comic and manga reader application with a niche but engaged user base, and its vulnerability profile centers on access-control and authentication weaknesses spanning improper restriction of excessive login attempts, missing authentication for critical functions, and server-side request forgery. Defenders deploying Kavita in multi-user or internet-accessible environments should prioritize authentication-boundary enforcement and input validation; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kavitareader over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3993CRITICAL Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.
| Nov 14, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-2756MEDIUM Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1. | Aug 10, 2022 | 6.5 | 26 | NO | YES |
CVE-2022-3945MEDIUM Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3. | Nov 11, 2022 | 5.3 | 21 | NO | NO |
Missing Authentication for Critical Function in GitHub repository kareadita/kavita prior to 0.7.0. | Feb 19, 2023 | 3.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kavitareader.
Media articles that mention a CVE ID that affects a product developed by Kavitareader — matched by CVE ID, not by vendor name.