Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Audiobookshelf

First CVE: Dec 13, 2023Active for: 3 yearsTotal CVEs: 12
38.8
VTI Score
Medium

Audiobookshelf is a self-hosted audiobook and podcast server platform with a companion mobile application, occupying a modestly represented but above-typical position in the vulnerability landscape. Its disclosed vulnerability profile centers on web-application input handling and information exposure, with recurring issues including cross-site scripting, server-side request forgery, path traversal, and improper handling of sensitive data in queries and responses that reflect the challenges of self-directed web services. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Audiobookshelf over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 13, 2023
2 years ago
Most Recent CVE
Feb 26, 2026
148 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-25205HIGH
Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticat
Feb 12, 20258.234NOYES
CVE-2025-57800HIGH
Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback URLs during OIDC authe
Aug 22, 20258.828NONO
CVE-2023-51697HIGH
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in `pod
Dec 27, 20237.522NONO
CVE-2023-51665HIGH
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in Auth
Dec 27, 20237.522NONO
CVE-2026-27973MEDIUM
Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile
Feb 26, 20264.820NONO
CVE-2026-27974MEDIUM
Audiobookshelf is a self-hosted audiobook and podcast server. A cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile applic
Feb 26, 20264.819NONO
CVE-2026-27963MEDIUM
Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.32.0 of the Audiobookshelf web applica
Feb 26, 20264.819NONO
CVE-2023-47624MEDIUM
Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to read files from the local file
Dec 13, 20236.519NONO
CVE-2025-46338MEDIUM
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulnerability in the `/api/upload` endpoint allows an attacker to
Apr 29, 20256.118NONO
CVE-2023-47619MEDIUM
Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, users with the update permission are able to read arbitrary files, delete arbitrary files
Dec 13, 20236.518NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
67%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (50.0%)
Unknown0 (0.0%)
Required6 (50.0%)
Privileges Required
Low3 (25.0%)
High4 (33.3%)
None5 (41.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
8.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Audiobookshelf.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Audiobookshelf — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Audiobookshelf's Products

View all 1 CNAs →

Top CWEs