Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Calibre — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in Calibre, with AI-generated Chinese analysis, references, and POCs.

This page aggregates data related to the Calibre e-book manager, focusing on vulnerability records, affected versions, and associated weakness categories. The collection includes security advisories and defect reports for the software, covering historical findings from the product's release history through the most recent disclosures. Readers can use this resource to track the vendor's published advisories, analyze specific weakness classes such as buffer overflows or path traversal issues, and review the chronological vulnerability history of the Calibre application. The dataset is organized to support threat assessment, patch management, and compliance verification, enabling users to identify exposed systems and prioritize remediation efforts based on severity and exploitability metrics. No individual CVE identifiers are listed in this introductory summary; instead, the page serves as a central hub for connecting product versions with their respective security incidents.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-73249 calibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation Modification CWE-862 7.5 High 2026-08-11
CVE-2026-73248 calibre: Bypass of Python template restrictions via nested `template()` leading to RCE CWE-94 8.5 High 2026-08-11
CVE-2026-53511 calibre: Arbitrary Code Execution in Template Formatter via Book Metadata CWE-94 8.5 High 2026-07-07
CVE-2026-33206 calibre has a path traversal vulnerability CWE-23 9.8 - 2026-03-27
CVE-2026-33205 calibre has Server-Side Request Forgery in ebook viewer backend CWE-918 8.6 - 2026-03-27
CVE-2026-30853 calibre has a Path Traversal Leading to Arbitrary File Write CWE-22 5.0 Medium 2026-03-13
CVE-2026-27824 calibre has IP Ban Bypass via X-Forwarded-For Header Spoofing CWE-307 5.3 Medium 2026-02-27
CVE-2026-27810 calibre Vulnerable to HTTP Response Header Injection CWE-113 6.4 Medium 2026-02-27
CVE-2026-26065 calibre: Path Traversal can Lead to Arbitrary File Write and Potential Code Execution CWE-22 8.8 - 2026-02-20
CVE-2026-26064 calibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code Execution CWE-22 8.8 - 2026-02-20
CVE-2026-25731 Calibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML Export CWE-1336 7.8 High 2026-02-06
CVE-2026-25635 calibre has a Path Traversal Leading to Arbitrary File Write and Potential Code Execution CWE-22 8.6 High 2026-02-06
CVE-2026-25636 calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execution CWE-22 8.2 High 2026-02-06
CVE-2025-64486 calibre is vulnerable to arbitrary code execution when opening FB2 files CWE-73 7.8 - 2025-11-07
CVE-2024-7009 Calibre SQL Injection CWE-89 4.2 Medium 2024-08-06
CVE-2024-7008 Calibre Reflected Cross-Site Scripting (XSS) CWE-79 5.4 Medium 2024-08-06
CVE-2024-6782 Calibre Remote Code Execution CWE-863 9.8 Critical 2024-08-06
CVE-2024-6781 Calibre Arbitrary File Read CWE-22 7.5 High 2024-08-06
CVE-2011-4126 Calibre 授权问题漏洞 CWE-367 8.1 - 2021-10-27
CVE-2011-4125 Calibre 代码问题漏洞 CWE-426 9.8 - 2021-10-27
CVE-2011-4124 Calibre 输入验证错误漏洞 CWE-20 9.8 - 2021-10-27

All 21 known CVE vulnerabilities affecting Calibre with full Chinese analysis, references, and POCs where available.