Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.
{ "urgency": "not yet assigned" }