{"id":"CVE-2022-30765","aliases":["GHSA-8ppf-x4gr-2x7g","PYSEC-2026-305"],"url":"https://o3.security/vulnerability/CVE-2022-30765","summary":"SQL injection in calibreweb","details":"Calibre-Web before 0.6.18 allows user table SQL Injection.","published":"2022-05-16T01:50:53Z","modified":"2026-08-12T03:51:13.192772969Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"calibreweb","fixedVersion":"0.6.18"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/janeczku/calibre-web/blob/master/SECURITY.md"},{"type":"WEB","url":"https://github.com/janeczku/calibre-web/releases/tag/0.6.18"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/30xxx/CVE-2022-30765.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-30765"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.192772969Z"}}