VendorsCalibre E-bookcalibreany version
Vulnerabilities

Calibre E-book Calibre any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2011-4125
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.
Published 2021-10-27 · Modified
10.0EPSS 0.023
CVE-2011-4124
Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.
Published 2021-10-27 · Modified
10.0EPSS 0.023
CVE-2011-4126
Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.
Published 2021-10-27 · Modified
9.3EPSS 0.015
CVE-2026-26064
calibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code Execution
Published 2026-02-20 · Analyzed
9.3EPSS 0.009
CVE-2026-26065
calibre: Path Traversal can Lead to Arbitrary File Write and Potential Code Execution
Published 2026-02-20 · Analyzed
9.3EPSS 0.006
CVE-2026-25635
calibre has a Path Traversal Leading to Arbitrary File Write and Potential Code Execution
Published 2026-02-06 · Analyzed
8.6EPSS 0.003
CVE-2026-33206
calibre has a path traversal vulnerability
Published 2026-03-27 · Analyzed
8.2EPSS 0.002
CVE-2026-30853
calibre has a Path Traversal Leading to Arbitrary File Write
Published 2026-03-13 · Analyzed
8.2EPSS 0.002
CVE-2026-25636
calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execution
Published 2026-02-06 · Analyzed
8.2EPSS 0.002
CVE-2026-25731
Calibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML Export
Published 2026-02-06 · Analyzed
7.8EPSS 0.003
CVE-2024-6781
Calibre Arbitrary File Read
Published 2024-08-06 · Analyzed
7.5EPSS 0.624
CVE-2021-44686
calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.
Published 2021-12-06 · Modified
7.5EPSS 0.050
CVE-2023-46303
link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root.
Published 2023-10-22 · Modified
7.5EPSS 0.014
CVE-2024-7009
Calibre SQL Injection
Published 2024-08-06 · Analyzed
7.1EPSS 0.139
CVE-2026-27810
calibre Vulnerable to HTTP Response Header Injection
Published 2026-02-27 · Analyzed
6.4EPSS 0.003
CVE-2024-7008
Calibre Reflected Cross-Site Scripting (XSS)
Published 2024-08-06 · Analyzed
6.1EPSS 0.256
CVE-2016-10187
The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.
Published 2017-03-16 · Modified
5.5EPSS 0.028
CVE-2026-33205
calibre has Server-Side Request Forgery in ebook viewer backend
Published 2026-03-27 · Analyzed
5.5EPSS 0.002
CVE-2026-27824
calibre has IP Ban Bypass via X-Forwarded-For Header Spoofing
Published 2026-02-27 · Analyzed
5.3EPSS 0.002