Vulnerabilities in bookwyrm-social
8 resultsVexday analysis
BookWyrm-social apresenta 5 vulnerabilidades catalogadas, com 1 classificada como crítica, todas relacionadas a falhas de autenticação (CWE-287). Nenhuma vulnerabilidade está sob exploração ativa conhecida e o portfólio não apresentou novas exposições nos últimos 90 dias, sugerindo risco contido no curto prazo. A concentração em deficiências de autenticação demanda revisão dos mecanismos de controle de acesso como medida preventiva.
CVE-2022-2651CRITICALAuthentication Bypass by Primary Weakness in bookwyrm-social/bookwyrmEPSS 15.8%CVE-2022-35925MEDIUMMissing rate limit in Authentication in bookwyrmEPSS 1.7%CVE-2022-23644HIGHServer-side request forgery in BookWyrmEPSS 0.9%CVE-2022-35953HIGHURL Redirection to Untrusted Site ('Open Redirect') in bookwyrmEPSS 0.6%CVE-2022-31136MEDIUMCross-site Scripting in BookWyrmEPSS 0.6%CVE-2026-86111HIGHBookWyrm through 0.9.1 Insecure Direct Object Reference in EditStatus Exposes Followers-Only and Direct StatusesEPSS 0.4%CVE-2026-86113HIGHBookWyrm through 0.9.1 Insecure Direct Object Reference in edit-readthrough Allows Tampering with Other Users' Reading RecordsEPSS 0.4%CVE-2026-86112MEDIUMBookWyrm through 0.9.1 Missing Authorization on the Favorite and Unfavorite EndpointsEPSS 0.3%