Calibre is a widely used open-source e-book management and conversion tool that, despite a narrow product footprint, holds a prominent position in digital publishing workflows and maintains an active user base across desktop environments. The vendor's vulnerability disclosures, concentrated in the single Calibre product, span a diverse range of attack surfaces inherent to document processing and file-format handling, though the specific weakness classes do not cluster into a narrow pattern. Defenders tracking this vendor should focus on timely patching of the primary product and be aware that vulnerabilities in document-processing tools can have supply-chain implications for publishing workflows; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Calibre Ebook over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6781HIGH Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read. | Aug 6, 2024 | 7.5 | 68 | NO | YES |
CVE-2024-7008MEDIUM Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting. | Aug 6, 2024 | 6.1 | 41 | NO | YES |
CVE-2011-4125CRITICAL A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root. | Oct 27, 2021 | 9.8 | 31 | NO | NO |
CVE-2011-4124CRITICAL Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges. | Oct 27, 2021 | 9.8 | 31 | NO | NO |
CVE-2026-26065HIGH calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers ( | Feb 20, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-26064HIGH calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arb | Feb 20, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-25635HIGH calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions | Feb 6, 2026 | 8.6 | 28 | NO | NO |
CVE-2024-7009HIGH Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database. | Aug 6, 2024 | 7.1 | 27 | NO | NO |
CVE-2021-44686HIGH calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py. | Dec 7, 2021 | 7.5 | 27 | NO | NO |
CVE-2026-25731HIGH calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a u | Feb 6, 2026 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Calibre Ebook.
Media articles that mention a CVE ID that affects a product developed by Calibre Ebook — matched by CVE ID, not by vendor name.