Stored Cross-Site Scripting Vulnerability in Audiobookshelf by Audiobookshelf
CVE-2026-27963

4.8MEDIUM

Key Information:

Vendor

Advplyr

Vendor
CVE Published:
26 February 2026

What is CVE-2026-27963?

The Audiobookshelf web application has a stored cross-site scripting security flaw that allows attackers with library modification privileges to inject arbitrary JavaScript through manipulated library metadata. If exploited, this vulnerability could lead to unauthorized code execution in the browsers of users accessing the affected application. Such attacks may facilitate session hijacking and sensitive data exposure. Users are advised to upgrade to version 2.32.0 or later, which addresses this vulnerability.

Affected Version(s)

audiobookshelf < 2.32.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.