I don't agree. That document states that the CVEs have historically required one of two preconditions:
> The attacker can submit and run arbitrary SQL statements.
> The attacker can submit a maliciously crafted database file to the application that the application will then open and query.
If you look at the actual list of CVEs, all but one start with ‘Malicious SQL statement’. The single one that doesn't is suffixed with ‘The bug never appeared in any official SQLite release’.
In other words, there has never been an official release of SQLite which was vulnerable when presented with a crafted database file.