CVE-2025-52880
MEDIUMDescription
Komga is a media server for comics, mangas, BDs, magazines and eBooks. A Cross-Site Scripting (XSS) vulnerability has been discovered in versions 1.8.0 through 1.21.3 when serving EPUB resources, either directly from the API, or when reading using the epub reader. The vulnerability lets an attacker perform actions on the victim's behalf. When targeting an admin user, this can be combined with controlling a server-side command to achieve arbitrary code execution. For this vulnerability to be exploited, a malicious EPUB file has to be present in a Komga library, and subsequently accessed in the Epub reader by an admin user. Version 1.22.0 contains a patch for the issue.
Is your site exposed to CVE-2025-52880?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2025-52880? +
How severe is CVE-2025-52880? +
How do I check if I'm vulnerable to CVE-2025-52880? +
Related Vulnerabilities
Letmein is an authenticating port knocker. Prior to version 10.2.1, The connection limiter is implemented incorrectly. It allows an arbitrary …
This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API …
This vulnerability exists in RupeeWeb trading platform due to missing rate limiting on OTP requests in certain API endpoints. An …
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an …
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation …
Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 …