← Vulnerability feed

Vulnerability record · CVE-2021-4171 · published 17 January 2022

CVE-2021-4171: Janeczku calibre-web vulnerability

JJaneczku · Calibre Web

calibre-web is vulnerable to Business Logic Errors

9.8 CVSS 3.1 Critical EPSS 1.4% · top 28.9% CWE-840 · CWE-840
9.8CVSS 3.1 base score, v2 7.5
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

calibre-web is vulnerable to Business Logic Errors

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-4171 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2022-0939Janeczku calibre-web server-side request forgery (ssrf) vulnerabilityServer-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.EPSS 1.1%9.9CVE-2022-0767Janeczku calibre-web server-side request forgery (ssrf) vulnerabilityServer-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.EPSS 0.99%9.8CVE-2023-2106Janeczku calibre-web weak password requirements vulnerabilityWeak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.EPSS 0.75%9.8CVE-2022-2525Janeczku calibre-web improper restriction of authentication attempts vulnerabilityImproper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.EPSS 0.77%9.8CVE-2022-30765Janeczku calibre-web sql injection vulnerabilityCalibre-Web before 0.6.18 allows user table SQL Injection.EPSS 1.2%9.8CVE-2022-0766Janeczku calibre-web server-side request forgery (ssrf) vulnerabilityServer-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.EPSS 1.3%9.8CVE-2022-0339Janeczku calibre-web server-side request forgery (ssrf) vulnerabilityServer-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.EPSS 0.96%9.8CVE-2020-12627Janeczku calibre-web hard-coded credentials vulnerabilityCalibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-4171), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.