MEDIUM🇵🇱 Wersja polska

CVE-2026-27963

CVSS 4.8v3.1pub. 2026-02-26upd. 2026-02-27

Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.32.0 of the Audiobookshelf web application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges can execute code in victim users' browsers, potentially leading to session hijacking and data exfiltration. Version 2.32.0 contains a patch for the issue.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
  • Audiobookshelf

    APP
    Audiobookshelf
    < 2.32.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2025-57800HIGH8.8same product

Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the applicati...

CVE-2025-25205HIGH8.2same product

Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version ...

CVE-2023-47624HIGH7.5same product

Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardles...

CVE-2023-47619HIGH8.1same product

Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the upda...

CVE-2026-27973MEDIUM4.0same product

Audiobookshelf to samodzielnie hostowany serwer audioboków i podcastów. Wersje aplikacji mobilnej Audiobookshe...