Junglewise Threat Intelligence

CVE-2025-65858: PYSEC-2026-1234 - Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation

CVE-2025-65858 · Severity: medium · CVSS 4 · Published 2026-07-07

Technologies: calibreweb (PyPI). Vendors: PyPI.

Executive brief

Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation

Affected products

  • PyPI calibreweb

Related threats