Unrated severityNVD Advisory· Published Jul 23, 2026· Updated Jul 28, 2026
Cal.com through 4.7.15 Cross-Site Scripting via booking questions
CVE-2024-58353
Description
Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/). Booking question (form field) labels are rendered via React's dangerouslySetInnerHTML without proper input sanitization or CSP, so an attacker who can create an event type with a malicious booking question label can inject arbitrary HTML/JavaScript that executes when a victim visits the booking view URL. Self-hosted instances with open registration are particularly at risk. The issue is fixed in version 4.7.16.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.