Cal.com
by Cal
Source repositories
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-23478 | Cri | 0.64 | 9.8 | 0.00 | Jan 13, 2026 | Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This… | ||
| CVE-2025-66489 | Cri | 0.64 | 9.8 | 0.01 | Dec 3, 2025 | Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic… | ||
| CVE-2024-58354 | Cri | 0.57 | 9.9 | 0.01 | Jul 23, 2026 | cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's default write permissions and passes them down to… | ||
| CVE-2023-37919 | Med | 0.42 | 6.5 | 0.00 | Jul 25, 2023 | Cal.com is open-source scheduling software. A vulnerability allows active sessions associated with an account to remain active even after enabling 2FA. When activating 2FA on a Cal.com account that is logged in on two or more devices, the account stays logged in on the other… | ||
| CVE-2023-1647 | Hig | 0.00 | 8.8 | 0.01 | Mar 27, 2023 | Improper Access Control in GitHub repository calcom/cal.com prior to 2.7. |
- risk 0.64cvss 9.8epss 0.00
Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This…
- risk 0.64cvss 9.8epss 0.01
Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic…
- risk 0.57cvss 9.9epss 0.01
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's default write permissions and passes them down to…
- risk 0.42cvss 6.5epss 0.00
Cal.com is open-source scheduling software. A vulnerability allows active sessions associated with an account to remain active even after enabling 2FA. When activating 2FA on a Cal.com account that is logged in on two or more devices, the account stays logged in on the other…
- risk 0.00cvss 8.8epss 0.01
Improper Access Control in GitHub repository calcom/cal.com prior to 2.7.