Audiobookshelf
4 CVEs tracked since 2023. Since Dec 2023, none of them reached CISA KEV.
Audiobookshelf CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-12 | 4 | 0 |
Products
The products that kept showing up in Audiobookshelf's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 10 most recently published vulnerabilities affecting Audiobookshelf.
- CVE-2026-27963Audiobookshelf has Stored XSS in Tooltip.vue via Audiobook Metadata4.8
- CVE-2025-57800Audiobookshelf vulnerable to OIDC token exfiltration and account takeover8.8
- CVE-2025-46338Audiobookshelf Vulnerable to Cross-Site-Scripting Reflected via POST Request in /api/upload6.1
- CVE-2025-25205Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching8.2
- CVE-2024-43797Path Traversal in audiobookshelf6.3
- CVE-2024-35236Audiobookshelf Cross-Site-Scripting vulnerability via crafted ebooks4.8
- CVE-2023-51665Audiobookshelf vulnerable to Blind SSRF in `Auth.js`4.3
- CVE-2023-51697Audiobookshelf vulnerable to Blind SSRF in `podcastUtils.js`4.3
- CVE-2023-47624Audiobookshelf Arbitrary File Read Vulnerability7.5
- CVE-2023-47619Audiobookshelf Server-Side Request Forgery and Arbitrary File Read Vulnerability8.1
The record
- Peak rank
- #161 in Dec 2023
- Busiest month shown
- Dec 2023, 4 CVEs
- Months with a KEV entry
- 0 since Dec 2023
- Monthly snapshots
- 1 since 2023