VDB

GCVE-VVD-MAGEIA-2025-49

GCVE-VVD-MAGEIA-2025-49
Advisory Published
Vulnetix · Advisory published May 14, 2025
link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root. (CVE-2023-46303) Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read. (CVE-2024-6781) Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution. (CVE-2024-6782) Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting. (CVE-2024-7008) Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database. (CVE-2024-7009)

Affected Products

VendorProductVersionsPlatforms
Mageiadpkg0 (affected), 1.22.11-1.mga9 (unaffected)
Mageiacalibre0 (affected), 6.17.0-1.1.mga9 (unaffected), 0 (affected), 6.17.0-1.1.mga9 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›