A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pc5g-j9j7-p4q3 Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 23 Dec 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Janeczku
Janeczku calibre-web
CPEs cpe:2.3:a:janeczku:calibre-web:0.6.25:*:*:*:*:*:*:*
Vendors & Products Janeczku
Janeczku calibre-web

Thu, 04 Dec 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Calibre-web Project
Calibre-web Project calibre-web
Vendors & Products Calibre-web Project
Calibre-web Project calibre-web

Tue, 02 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 14:00:00 +0000

Type Values Removed Values Added
Description A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-02T15:12:48.645Z

Reserved: 2025-11-18T00:00:00.000Z

Link: CVE-2025-65858

cve-icon Vulnrichment

Updated: 2025-12-02T15:12:40.377Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-02T14:16:25.233

Modified: 2025-12-23T13:08:42.720

Link: CVE-2025-65858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-04T16:49:03Z

Weaknesses