Low severity3.3NVD Advisory· Published Dec 5, 2025· Updated Jun 17, 2026
CVE-2025-66546
CVE-2025-66546
Description
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10<4.7.19, <5.5.6, <6.0.1+ 8 more
- (no CPE)range: <4.7.19, <5.5.6, <6.0.1
- cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:*range: >=4.0.0,<4.7.19
- cpe:2.3:a:nextcloud:calendar:6.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:nextcloud:calendar:6.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:nextcloud:calendar:6.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:nextcloud:calendar:6.0.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:nextcloud:calendar:6.0.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:nextcloud:calendar:6.0.0:rc5:*:*:*:*:*:*
- cpe:2.3:a:nextcloud:calendar:6.0.0:rc6:*:*:*:*:*:*
- Range: >= 6.0.0-rc.1, < 6.0.1
Patches
Vulnerability mechanics
References
4- github.com/nextcloud/calendar/commit/f41650c3681fc4a4130eb883f5c0899c011326b3nvdPatch
- github.com/nextcloud/security-advisories/security/advisories/GHSA-7x2j-2674-fj95nvdPatchVendor Advisory
- hackerone.com/reports/3275810nvdIssue TrackingVendor Advisory
- github.com/nextcloud/calendar/pull/7537nvdIssue Tracking
News mentions
0No linked articles in our index yet.