CVE-2025-7404Medium▾ TwilightPoC availableCalibre Web and Autocaliweb have OS Command Injection vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 27.5 · likelihood 0.6 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.7%
2.7% → 2.8%
1 GitHub repo
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.
calibreweb <= 0.6.24Refer to the advisory for the patched release.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-6998HighCalibre Web and Autocaliweb have a ReDoS vulnerability
CVE-2025-65858LowCalibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
CVE-2024-39123Medium· 5.4Calibre-Web Cross Site Scripting (XSS)
CVE-2021-4164High· 7.6calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4170Medium· 5.4calibre-web is vulnerable to Cross-site Scripting
CVE-2021-3988Medium· 6.1Cross-site Scripting (XSS) - DOM in janeczku/calibre-web