Known Vulnerabilities for Calibre-web by Calibre-web Project
Listed below are 10 of the newest known vulnerabilities associated with "Calibre-web" by "Calibre-web Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-53511 json | calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its ... | Not Provided | 2026-07-07 | 2026-07-09 |
| CVE-2026-7714 json | A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionali... | Not Provided | 2026-05-04 | 2026-05-04 |
| CVE-2026-7713 json | A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the funct... | Not Provided | 2026-05-04 | 2026-05-04 |
| CVE-2026-7709 json | A vulnerability was identified in janeczku Calibre-Web up to 0.6.26. The impacted element is the function generate_auth_token... | Not Provided | 2026-05-03 | 2026-05-04 |
| CVE-2023-2106 json | Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. | 9.8 - CRITICAL | 2023-04-15 | 2023-04-25 |
| CVE-2022-30765 json | Calibre-Web before 0.6.18 allows user table SQL Injection. | 9.8 - CRITICAL | 2022-05-16 | 2022-05-24 |
| CVE-2022-2525 json | Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. | 9.8 - CRITICAL | 2023-04-15 | 2023-04-24 |
| CVE-2022-0990 json | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | 9.1 - CRITICAL | 2022-04-04 | 2022-04-12 |
| CVE-2022-0939 json | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | 9.9 - CRITICAL | 2022-04-04 | 2022-04-11 |
| CVE-2022-0767 json | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. | 9.9 - CRITICAL | 2022-03-07 | 2022-03-14 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Calibre-web Project | Calibre-web | 0.6.6 | |||
| Application | Calibre-web Project | Calibre-web | 0.6.5 | |||
| Application | Calibre-web Project | Calibre-web | 0.6.4 | |||
| Application | Calibre-web Project | Calibre-web | 0.6.3 | |||
| Application | Calibre-web Project | Calibre-web | 0.6.2 | |||
| Application | Calibre-web Project | Calibre-web | 0.6.0 |