Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Calibre Ebook

First CVE: —Active for: N/ATotal CVEs: 20

Calibre is a widely used open-source e-book management and conversion tool that, despite a narrow product footprint, holds a prominent position in digital publishing workflows and maintains an active user base across desktop environments. The vendor's vulnerability disclosures, concentrated in the single Calibre product, span a diverse range of attack surfaces inherent to document processing and file-format handling, though the specific weakness classes do not cluster into a narrow pattern. Defenders tracking this vendor should focus on timely patching of the primary product and be aware that vulnerabilities in document-processing tools can have supply-chain implications for publishing workflows; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Calibre Ebook over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2017
9 years ago
Most Recent CVE
Mar 27, 2026
123 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-6781HIGH
Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.
Aug 6, 20247.568NOYES
CVE-2024-7008MEDIUM
Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.
Aug 6, 20246.141NOYES
CVE-2011-4125CRITICAL
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.
Oct 27, 20219.831NONO
CVE-2011-4124CRITICAL
Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.
Oct 27, 20219.831NONO
CVE-2026-26065HIGH
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (
Feb 20, 20268.830NONO
CVE-2026-26064HIGH
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arb
Feb 20, 20268.829NONO
CVE-2026-25635HIGH
calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions
Feb 6, 20268.628NONO
CVE-2024-7009HIGH
Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.
Aug 6, 20247.127NONO
CVE-2021-44686HIGH
calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.
Dec 7, 20217.527NONO
CVE-2026-25731HIGH
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a u
Feb 6, 20267.826NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
30%
60%
10%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local8 (40.0%)
Network12 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (95.0%)
High1 (5.0%)
Unknown0 (0.0%)
User Interaction
None11 (55.0%)
Unknown0 (0.0%)
Required9 (45.0%)
Privileges Required
Low4 (20.0%)
High0 (0.0%)
None16 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
10.0% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Calibre Ebook.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Calibre Ebook — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Calibre Ebook's Products

View all 4 CNAs →

Top CWEs