📦 Calibre

by Calibre Ebook

🔍 What is Calibre?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2011-4124

CRITICAL CVSS 9.8 Oct 27, 2021

CVE-2011-4124 is a privilege escalation vulnerability in Calibre's Linux mount helper that allows local attackers to execute arbitrary commands with root privileges. The vulnerability exists due to im...

CVE-2026-26065

HIGH CVSS 8.8 Feb 20, 2026

CVE-2026-26065 is a path traversal vulnerability in calibre's PDB readers that allows attackers to write arbitrary files anywhere the user has write permissions. This can lead to code execution, denia...

CVE-2026-25731

HIGH CVSS 7.8 Feb 6, 2026

A Server-Side Template Injection vulnerability in Calibre's Templite engine allows arbitrary code execution when converting ebooks using malicious custom templates via command-line options. This affec...

CVE-2026-25635

HIGH CVSS 8.6 Feb 6, 2026

Calibre e-book manager versions before 9.2.0 contain a path traversal vulnerability in the CHM reader that allows attackers to write arbitrary files anywhere the user has write permissions. On Windows...

CVE-2026-25636

HIGH CVSS 8.2 Feb 6, 2026

A path traversal vulnerability in Calibre's EPUB conversion allows malicious EPUB files to corrupt arbitrary files writable by the Calibre process. Attackers can exploit this by crafting EPUB files wi...

CVE-2024-6781

HIGH CVSS 7.5 Aug 6, 2024

CVE-2024-6781 is a path traversal vulnerability in Calibre ebook management software that allows unauthenticated attackers to read arbitrary files from the server filesystem. This affects all Calibre ...

CVE-2023-46303

HIGH CVSS 7.5 Oct 22, 2023

This vulnerability in calibre's HTML conversion plugin allows Server-Side Request Forgery (SSRF) by default, enabling attackers to access resources outside the document root. It affects calibre users ...

CVE-2011-4126

HIGH CVSS 8.1 Oct 27, 2021

CVE-2011-4126 is a race condition vulnerability in Calibre's Linux mount helper that allows unprivileged local users to mount arbitrary devices to any location on the filesystem. This affects Linux sy...

CVE-2024-7008

MEDIUM CVSS 5.4 Aug 6, 2024

Calibre versions up to 7.15.0 contain a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. Attackers can inject malicious scripts that execute in users' browsers wh...