Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

calibre — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in calibre, with AI-generated Chinese analysis, references, and POCs.

This page serves as a vulnerability aggregation hub for the open-source ebook management software Calibre, focusing on Common Weakness Enumeration classifications and related security tags. It compiles a comprehensive record of known security flaws, configuration errors, and design vulnerabilities affecting Calibre and its underlying dependencies, covering incidents reported from early development phases through the most recent stable releases. By consolidating data from vendor advisories, community reports, and security databases, this resource allows users to track the publication timeline of Calibre-specific security notices, gain a deeper understanding of prevalent weakness classes such as buffer overflows and path traversal issues within the application’s codebase, and review the historical progression of vulnerabilities associated with specific software versions. The information is organized to facilitate efficient lookup and analysis, enabling developers, system administrators, and security researchers to assess risk exposure and apply appropriate mitigation strategies without navigating disparate sources. All entries are sourced from publicly available disclosures and verified reports to ensure accuracy and relevance for ongoing maintenance and security auditing purposes.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-73249 calibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation Modification CWE-862 7.5 High2026-08-11
CVE-2026-73248 calibre: Bypass of Python template restrictions via nested `template()` leading to RCE CWE-94 8.5 High2026-08-11
CVE-2026-53511 calibre: Arbitrary Code Execution in Template Formatter via Book Metadata CWE-94--2026-07-07
CVE-2026-33206 calibre has a path traversal vulnerability CWE-23 9.8 -2026-03-27
CVE-2026-33205 calibre has Server-Side Request Forgery in ebook viewer backend CWE-918 8.6 -2026-03-27
CVE-2026-30853 calibre has a Path Traversal Leading to Arbitrary File Write CWE-22 5.0 Medium2026-03-13
CVE-2026-27824 calibre has IP Ban Bypass via X-Forwarded-For Header Spoofing CWE-307 5.3 Medium2026-02-27
CVE-2026-27810 calibre Vulnerable to HTTP Response Header Injection CWE-113 6.4 Medium2026-02-27
CVE-2026-26065 calibre: Path Traversal can Lead to Arbitrary File Write and Potential Code Execution CWE-22 8.8 -2026-02-20
CVE-2026-26064 calibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code Execution CWE-22 8.8 -2026-02-20
CVE-2026-25731 Calibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML Export CWE-1336 7.8 High2026-02-06
CVE-2026-25635 calibre has a Path Traversal Leading to Arbitrary File Write and Potential Code Execution CWE-22 8.6 High2026-02-06
CVE-2026-25636 calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execution CWE-22 8.2 High2026-02-06
CVE-2025-64486 calibre is vulnerable to arbitrary code execution when opening FB2 files CWE-73 7.8 -2025-11-07
CVE-2024-7009 Calibre SQL Injection CWE-89 4.2 Medium2024-08-06
CVE-2024-7008 Calibre Reflected Cross-Site Scripting (XSS) CWE-79 5.4 Medium2024-08-06
CVE-2024-6782 Calibre Remote Code Execution CWE-863 9.8 Critical2024-08-06
CVE-2024-6781 Calibre Arbitrary File Read CWE-22 7.5 High2024-08-06
CVE-2011-4126 Calibre 授权问题漏洞 CWE-367 8.1 -2021-10-27
CVE-2011-4125 Calibre 代码问题漏洞 CWE-426 9.8 -2021-10-27
CVE-2011-4124 Calibre 输入验证错误漏洞 CWE-20 9.8 -2021-10-27

All 21 known CVE vulnerabilities affecting calibre with full Chinese analysis, references, and POCs where available.