VYPR

calibre

by calibre

Source repositories

CVEs (23)

  • CVE-2026-25731HigFeb 6, 2026
    risk 0.00cvss 7.8epss 0.00

    calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or…

  • CVE-2026-25636HigFeb 6, 2026
    risk 0.00cvss 8.2epss 0.00

    calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre resolves CipherReference URI from…

  • CVE-2026-25635HigFeb 6, 2026
    risk 0.00cvss 8.6epss 0.00

    calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a…

Page 2 of 2