📦 Calibre Web

by Janeczku

🔍 What is Calibre Web?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-2106

CRITICAL CVSS 9.8 Apr 15, 2023

CVE-2023-2106 is a critical authentication vulnerability in Calibre-Web that allows attackers to bypass weak password requirements and gain unauthorized access. This affects all users running Calibre-...

CVE-2022-2525

CRITICAL CVSS 9.8 Apr 15, 2023

CVE-2022-2525 is an authentication brute-force vulnerability in Calibre-Web that allows attackers to make unlimited login attempts without rate limiting. This affects all users running Calibre-Web ver...

CVE-2022-30765

CRITICAL CVSS 9.8 May 16, 2022

CVE-2022-30765 is a SQL injection vulnerability in Calibre-Web's user table functionality that allows attackers to execute arbitrary SQL commands. This affects all Calibre-Web instances running versio...

CVE-2022-0990

CRITICAL CVSS 9.1 Apr 4, 2022

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Calibre-Web, an open-source web application for managing eBook collections. The vulnerability allows attackers to make unauthor...

CVE-2022-0939

CRITICAL CVSS 9.9 Apr 4, 2022

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Calibre-Web, an open-source web application for managing eBook collections. Attackers can exploit this vulnerability to make th...

CVE-2022-0766

CRITICAL CVSS 9.8 Mar 7, 2022

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Calibre-Web, an open-source web application for managing eBook collections. Attackers can exploit this to make the server send ...

CVE-2022-0339

CRITICAL CVSS 9.8 Jan 30, 2022

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in calibre-web versions prior to 0.6.16. Attackers can exploit this to make the server send arbitrary HTTP requests to internal sy...

CVE-2021-25965

HIGH CVSS 8.8 Nov 16, 2021

Calibre-web versions 0.6.0 to 0.6.13 contain a CSRF vulnerability that allows attackers to create admin accounts with attacker-controlled credentials. This affects all users running vulnerable version...

CVE-2021-3987

MEDIUM CVSS 4.3 Nov 15, 2024

This vulnerability allows users without proper permissions to create public shelves in Calibre-Web, potentially exposing sensitive book collections. It affects all Calibre-Web instances where user acc...

CVE-2025-65858

LOW CVSS 3.5 Dec 2, 2025

A stored cross-site scripting vulnerability in Calibre-Web allows attackers to inject malicious JavaScript into username fields during user creation. The payload executes when administrators view the ...