Browse all 5 CVE security advisories affecting kareadita. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Kareadita is a web application primarily used for content management and e-commerce platforms. Historically, it has been vulnerable to multiple security issues including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. The application has demonstrated consistent weaknesses in input validation and access control mechanisms, leading to its five recorded CVEs. While no major public security incidents have been widely documented, the pattern of vulnerabilities suggests potential risks for unpatched deployments. Security researchers have noted that timely updates and proper configuration are critical for mitigating the identified security flaws in this content management solution.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-39307 | Cross-Site Scripting (XSS) vulnerability via crafted ebooks in Kavita — KavitaCWE-79 | 3.5 | Low | 2024-06-28 |
| CVE-2023-0919 | Missing Authentication for Critical Function in kareadita/kavita — kareadita/kavitaCWE-306 | 8.1 | High | 2023-02-19 |
| CVE-2022-3993 | Improper Restriction of Excessive Authentication Attempts in kareadita/kavita — kareadita/kavitaCWE-307 | 9.4 | Critical | 2022-11-14 |
| CVE-2022-3945 | Improper Restriction of Excessive Authentication Attempts in kareadita/kavita — kareadita/kavitaCWE-307 | 7.5 | - | 2022-11-11 |
| CVE-2022-2756 | Server-Side Request Forgery (SSRF) in kareadita/kavita — kareadita/kavitaCWE-918 | 6.5 | - | 2022-08-10 |
This page lists every published CVE security advisory associated with kareadita. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.