« Volver al listado

Calibre-ebook

Calibre-ebook Calibre: vulnerabilidades y CVE

Calibre-ebook Calibre tiene 25 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE25
Últimos 12 meses14
Críticas6
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-73249Alta (7.5)0.44%—11 ago 2026
calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing…
CVE-2026-73248Alta (8.5)0.20%—11 ago 2026
calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose…
CVE-2026-53511Alta (8.5)0.20%—7 jul 2026
calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read by calibre, including through Add books or Edit books, by embedding a custom…
CVE-2026-33206Alta (8.2)0.22%—27 mar 2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other…
CVE-2026-33205Media (4.8)0.17%—27 mar 2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book…
CVE-2026-30853Alta (8.2)0.19%—13 mar 2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability in the RocketBook (.rb) input plugin (src/calibre/ebooks/rb/reader.py)…
CVE-2026-27824Media (5.3)0.19%—27 feb 2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, the calibre Content Server's brute-force protection mechanism uses a ban key derived from both…
CVE-2026-27810Media (6.4)0.32%—27 feb 2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, an HTTP Response Header Injection vulnerability in the calibre Content Server allows any…
CVE-2026-26065Crítica (9.3)0.56%—20 feb 2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-byte and 202-byte header…
CVE-2026-26064Crítica (9.3)0.85%—20 feb 2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arbitrary file writes anywhere the user…
CVE-2026-25731Alta (7.8)0.29%—6 feb 2026
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious…
CVE-2026-25636Alta (7.8)0.18%—6 feb 2026
calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During…
CVE-2026-25635Alta (8.6)0.40%—6 feb 2026
calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other…
CVE-2025-64486Crítica (9.3)0.18%—8 nov 2025
calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the filesystem when viewing or…
CVE-2024-7009Alta (7.1)14%—6 ago 2024
Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.
CVE-2024-7008Media (6.1)26%—6 ago 2024
Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting.
CVE-2024-6782Crítica (9.8)84%—6 ago 2024
Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
CVE-2024-6781Alta (7.5)62%—6 ago 2024
Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.
CVE-2023-46303Alta (7.5)1.3%—22 oct 2023
link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root.
CVE-2021-44686Alta (7.5)5.2%—7 dic 2021
calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.
CVE-2011-4126Alta (8.1)1.5%—27 oct 2021
Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.
CVE-2011-4125Crítica (9.8)2.3%—27 oct 2021
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.
CVE-2011-4124Crítica (9.8)2.3%—27 oct 2021
Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.
CVE-2018-7889Alta (7.8)4.5%—8 mar 2018
gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that…
CVE-2016-10187Media (5.5)2.8%—16 mar 2017
The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution10
  2. T1059 Command and Scripting Interpreter5
  3. T1565.001 Stored Data Manipulation3
  4. T1005 Data from Local System1
  5. T1190 Exploit Public-Facing Application1
  6. T1565 Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.