{"schema_version":1,"title":"calibreweb (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 18 vulnerabilities in calibreweb (PyPI): 0 in the last 7 days and 15 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-65858, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/calibreweb","json_url":"https://junglewise.ai/threats/technologies/calibreweb.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/calibreweb","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":18,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":15,"last_365_days":15},"latest":[{"cve":"CVE-2025-65858","cvss":4,"epss":0.0021,"slug":"cve-2025-65858-calibre-web-has-a-stored-cross-site-scripting-xss-vulnerability","title":"PYSEC-2026-1234 - Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:11.806566+00:00","url":"https://junglewise.ai/threats/cve-2025-65858-calibre-web-has-a-stored-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2025-6998","cvss":4,"epss":0.0084,"slug":"cve-2025-6998-calibre-web-and-autocaliweb-redos-in-strip-whitespaces","title":"PYSEC-2026-1228 - Calibre Web and Autocaliweb have a ReDoS vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:58.600303+00:00","url":"https://junglewise.ai/threats/cve-2025-6998-calibre-web-and-autocaliweb-redos-in-strip-whitespaces"},{"cve":"CVE-2025-7404","cvss":4,"epss":0.0275,"slug":"cve-2025-7404-calibre-web-and-autocaliweb-have-os-command-injection","title":"PYSEC-2026-1235 - Calibre Web and Autocaliweb have OS Command Injection vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:58.532715+00:00","url":"https://junglewise.ai/threats/cve-2025-7404-calibre-web-and-autocaliweb-have-os-command-injection"},{"cve":"CVE-2021-3986","cvss":3.1,"epss":0.0037,"slug":"cve-2021-3986-generation-of-error-message-containing-sensitive-information-in","title":"PYSEC-2026-1232 - Generation of Error Message Containing Sensitive Information in janeczku/calibre-web","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:44.756067+00:00","url":"https://junglewise.ai/threats/cve-2021-3986-generation-of-error-message-containing-sensitive-information-in"},{"cve":"CVE-2021-3988","cvss":3.1,"epss":0.0036,"slug":"cve-2021-3988-cross-site-scripting-xss-dom-in-janeczku-calibre-web","title":"PYSEC-2026-1236 - Cross-site Scripting (XSS) - DOM in janeczku/calibre-web","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:44.701918+00:00","url":"https://junglewise.ai/threats/cve-2021-3988-cross-site-scripting-xss-dom-in-janeczku-calibre-web"},{"cve":"CVE-2021-3987","cvss":3,"epss":0.0035,"slug":"cve-2021-3987-improper-access-control-in-janeczku-calibre-web","title":"PYSEC-2026-1229 - Improper Access Control in janeczku/calibre-web","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:44.645886+00:00","url":"https://junglewise.ai/threats/cve-2021-3987-improper-access-control-in-janeczku-calibre-web"},{"cve":"CVE-2024-39123","cvss":3.1,"epss":0.2307,"slug":"cve-2024-39123-calibre-web-cross-site-scripting-xss","title":"PYSEC-2026-1230 - Calibre-Web Cross Site Scripting (XSS)","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:37.138202+00:00","url":"https://junglewise.ai/threats/cve-2024-39123-calibre-web-cross-site-scripting-xss"},{"cve":"CVE-2022-2525","epss":0.0077,"slug":"cve-2022-2525-improper-restriction-of-excessive-authentication-attempts-in","title":"PYSEC-2026-1231 - Improper Restriction of Excessive Authentication Attempts in calibreweb","severity":"info","exploited":false,"published_at":"2026-07-07T11:45:18.433911+00:00","url":"https://junglewise.ai/threats/cve-2022-2525-improper-restriction-of-excessive-authentication-attempts-in"},{"cve":"CVE-2023-2106","cvss":3,"epss":0.0075,"slug":"cve-2023-2106-weak-password-requirements-in-calibreweb","title":"PYSEC-2026-1233 - Weak Password Requirements in calibreweb","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:18.35753+00:00","url":"https://junglewise.ai/threats/cve-2023-2106-weak-password-requirements-in-calibreweb"},{"cve":"CVE-2021-4170","cvss":3.1,"epss":0.0081,"slug":"cve-2021-4170-calibre-web-is-vulnerable-to-cross-site-scripting","title":"PYSEC-2026-620 - calibre-web is vulnerable to Cross-site Scripting","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:14.959672+00:00","url":"https://junglewise.ai/threats/cve-2021-4170-calibre-web-is-vulnerable-to-cross-site-scripting"},{"cve":"CVE-2021-4164","cvss":3,"epss":0.0055,"slug":"cve-2021-4164-calibre-web-is-vulnerable-to-cross-site-request-forgery-csrf","title":"PYSEC-2026-621 - calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:14.881686+00:00","url":"https://junglewise.ai/threats/cve-2021-4164-calibre-web-is-vulnerable-to-cross-site-request-forgery-csrf"},{"cve":"CVE-2021-4171","cvss":3.1,"epss":0.0139,"slug":"cve-2021-4171-calibre-web-is-vulnerable-to-business-logic-errors","title":"PYSEC-2026-307 - calibre-web is vulnerable to Business Logic Errors","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:33.865743+00:00","url":"https://junglewise.ai/threats/cve-2021-4171-calibre-web-is-vulnerable-to-business-logic-errors"},{"cve":"CVE-2022-30765","cvss":3.1,"epss":0.0119,"slug":"cve-2022-30765-sql-injection-in-calibreweb","title":"PYSEC-2026-305 - SQL injection in calibreweb","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:32.663521+00:00","url":"https://junglewise.ai/threats/cve-2022-30765-sql-injection-in-calibreweb"},{"cve":"CVE-2022-0767","cvss":3.1,"epss":0.0099,"slug":"cve-2022-0767-server-side-request-forgery-in-calibreweb","title":"PYSEC-2026-306 - Server-Side Request Forgery in calibreweb","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:32.05263+00:00","url":"https://junglewise.ai/threats/cve-2022-0767-server-side-request-forgery-in-calibreweb"},{"cve":"CVE-2022-0766","cvss":3.1,"epss":0.0132,"slug":"cve-2022-0766-calibreweb-server-side-request-forgery-in-cover-upload","title":"PYSEC-2026-304 - Server-Side Request Forgery in calibreweb","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:32.006359+00:00","url":"https://junglewise.ai/threats/cve-2022-0766-calibreweb-server-side-request-forgery-in-cover-upload"},{"cve":"CVE-2022-0273","cvss":3.1,"epss":0.0067,"slug":"cve-2022-0273-incorrect-authorization-in-calibreweb","title":"PYSEC-2022-22 - Improper Access Control in Pypi calibreweb prior to 0.6.16.","severity":"low","exploited":false,"published_at":"2022-01-30T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-0273-incorrect-authorization-in-calibreweb"},{"cve":"CVE-2022-0339","cvss":3,"epss":0.0096,"slug":"cve-2022-0339-server-side-request-forgery-in-calibreweb","title":"PYSEC-2022-23 - Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.","severity":"low","exploited":false,"published_at":"2022-01-30T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-0339-server-side-request-forgery-in-calibreweb"},{"cve":"CVE-2022-0352","cvss":3.1,"epss":0.0085,"slug":"cve-2022-0352-cross-site-scripting-in-calibreweb","title":"PYSEC-2022-18 - Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16.","severity":"low","exploited":false,"published_at":"2022-01-28T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-0352-cross-site-scripting-in-calibreweb"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"calibreweb (PyPI)","slug":"calibreweb","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/calibreweb"},"most_severe":[{"cve":"CVE-2025-7404","cvss":4,"epss":0.0275,"slug":"cve-2025-7404-calibre-web-and-autocaliweb-have-os-command-injection","title":"PYSEC-2026-1235 - Calibre Web and Autocaliweb have OS Command Injection vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:58.532715+00:00","url":"https://junglewise.ai/threats/cve-2025-7404-calibre-web-and-autocaliweb-have-os-command-injection"},{"cve":"CVE-2025-6998","cvss":4,"epss":0.0084,"slug":"cve-2025-6998-calibre-web-and-autocaliweb-redos-in-strip-whitespaces","title":"PYSEC-2026-1228 - Calibre Web and Autocaliweb have a ReDoS vulnerability","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:58.600303+00:00","url":"https://junglewise.ai/threats/cve-2025-6998-calibre-web-and-autocaliweb-redos-in-strip-whitespaces"},{"cve":"CVE-2025-65858","cvss":4,"epss":0.0021,"slug":"cve-2025-65858-calibre-web-has-a-stored-cross-site-scripting-xss-vulnerability","title":"PYSEC-2026-1234 - Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:11.806566+00:00","url":"https://junglewise.ai/threats/cve-2025-65858-calibre-web-has-a-stored-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2024-39123","cvss":3.1,"epss":0.2307,"slug":"cve-2024-39123-calibre-web-cross-site-scripting-xss","title":"PYSEC-2026-1230 - Calibre-Web Cross Site Scripting (XSS)","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:37.138202+00:00","url":"https://junglewise.ai/threats/cve-2024-39123-calibre-web-cross-site-scripting-xss"},{"cve":"CVE-2021-4171","cvss":3.1,"epss":0.0139,"slug":"cve-2021-4171-calibre-web-is-vulnerable-to-business-logic-errors","title":"PYSEC-2026-307 - calibre-web is vulnerable to Business Logic Errors","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:33.865743+00:00","url":"https://junglewise.ai/threats/cve-2021-4171-calibre-web-is-vulnerable-to-business-logic-errors"},{"cve":"CVE-2022-0766","cvss":3.1,"epss":0.0132,"slug":"cve-2022-0766-calibreweb-server-side-request-forgery-in-cover-upload","title":"PYSEC-2026-304 - Server-Side Request Forgery in calibreweb","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:32.006359+00:00","url":"https://junglewise.ai/threats/cve-2022-0766-calibreweb-server-side-request-forgery-in-cover-upload"},{"cve":"CVE-2022-30765","cvss":3.1,"epss":0.0119,"slug":"cve-2022-30765-sql-injection-in-calibreweb","title":"PYSEC-2026-305 - SQL injection in calibreweb","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:32.663521+00:00","url":"https://junglewise.ai/threats/cve-2022-30765-sql-injection-in-calibreweb"},{"cve":"CVE-2022-0767","cvss":3.1,"epss":0.0099,"slug":"cve-2022-0767-server-side-request-forgery-in-calibreweb","title":"PYSEC-2026-306 - Server-Side Request Forgery in calibreweb","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:32.05263+00:00","url":"https://junglewise.ai/threats/cve-2022-0767-server-side-request-forgery-in-calibreweb"},{"cve":"CVE-2022-0352","cvss":3.1,"epss":0.0085,"slug":"cve-2022-0352-cross-site-scripting-in-calibreweb","title":"PYSEC-2022-18 - Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16.","severity":"low","exploited":false,"published_at":"2022-01-28T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-0352-cross-site-scripting-in-calibreweb"},{"cve":"CVE-2021-4170","cvss":3.1,"epss":0.0081,"slug":"cve-2021-4170-calibre-web-is-vulnerable-to-cross-site-scripting","title":"PYSEC-2026-620 - calibre-web is vulnerable to Cross-site Scripting","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:14.959672+00:00","url":"https://junglewise.ai/threats/cve-2021-4170-calibre-web-is-vulnerable-to-cross-site-scripting"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}