Audiobookshelf is a self-hosted audiobook and podcast server platform with a companion mobile application, occupying a modestly represented but above-typical position in the vulnerability landscape. Its disclosed vulnerability profile centers on web-application input handling and information exposure, with recurring issues including cross-site scripting, server-side request forgery, path traversal, and improper handling of sensitive data in queries and responses that reflect the challenges of self-directed web services. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Audiobookshelf over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-25205HIGH Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticat | Feb 12, 2025 | 8.2 | 34 | NO | YES |
CVE-2025-57800HIGH Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback URLs during OIDC authe | Aug 22, 2025 | 8.8 | 28 | NO | NO |
CVE-2023-51697HIGH Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in `pod | Dec 27, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-51665HIGH Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in Auth | Dec 27, 2023 | 7.5 | 22 | NO | NO |
CVE-2026-27973MEDIUM Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile | Feb 26, 2026 | 4.8 | 20 | NO | NO |
CVE-2026-27974MEDIUM Audiobookshelf is a self-hosted audiobook and podcast server. A cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile applic | Feb 26, 2026 | 4.8 | 19 | NO | NO |
CVE-2026-27963MEDIUM Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.32.0 of the Audiobookshelf web applica | Feb 26, 2026 | 4.8 | 19 | NO | NO |
CVE-2023-47624MEDIUM Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to read files from the local file | Dec 13, 2023 | 6.5 | 19 | NO | NO |
CVE-2025-46338MEDIUM Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulnerability in the `/api/upload` endpoint allows an attacker to | Apr 29, 2025 | 6.1 | 18 | NO | NO |
CVE-2023-47619MEDIUM Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrary files, delete arbitrary files | Dec 13, 2023 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Audiobookshelf.
Media articles that mention a CVE ID that affects a product developed by Audiobookshelf — matched by CVE ID, not by vendor name.