Known vulnerabilities in Kavita

Vendor: Kareadita
Software: Kavita
Software CPE: cpe:2.3:a:kareadita:kavita:*:*:*:*:*:*:*:*
Total vulnerabilities: 13
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Kavita Kavita is affected by 13 known vulnerabilities: 1 high, 1 medium, 11 low Critical High Medium Low

Vulnerabilities (13)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU147285 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
0.9.1.0 07.09.2026 SB2026090788
#VU147284 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
0.9.1.0 07.09.2026 SB2026090788
#VU147282 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
0.9.1.0 07.09.2026 SB2026090788
#VU147283 - Missing Authorization
CWE-862 Low
No
No
0.9.1.0 07.09.2026 SB2026090788
#VU147281 - Missing Authorization
CWE-862 Low
No
No
0.9.1.0 07.09.2026 SB2026090788
#VU147280 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
0.9.1.0 07.09.2026 SB2026090788
#VU147279 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
0.9.1.0 07.09.2026 SB2026090788
#VU147278 - Authorization Bypass Through User-Controlled Key
CWE-639 Low
No
No
0.9.1.0 07.09.2026 SB2026090788
#VU147277 - Incorrect Authorization
CWE-863 Low
No
No
0.9.1.0 07.09.2026 SB2026090788
#VU131933 - Improper Authentication
CVE-2026-47202
CWE-287 High
No
No
0.9.0.2 20.05.2026 SB2026052058
#VU130157 - Authorization Bypass Through User-Controlled Key
CVE-2026-44776
CWE-639 Low
No
No
0.8.9.1 05.05.2026 SB20260505103
#VU130156 - Missing Authentication for Critical Function
CVE-2026-44775
CWE-306 Medium
No
No
0.9.0 05.05.2026 SB20260505102
#VU93657 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-39307
CWE-79 Low
No
No
0.8.0 02.07.2024 SB2024070278