VYPR

cal.diy

by Calcom

Source repositories

CVEs (7)

  • CVE-2025-71389CriJul 23, 2026
    risk 0.58cvss 10.0epss 0.01

    Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to…

  • CVE-2024-58354CriJul 23, 2026
    risk 0.57cvss 9.9epss 0.00

    cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's default write permissions and passes them down to…

  • CVE-2024-58355HigJul 23, 2026
    risk 0.51cvss 8.9epss 0.00

    Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/) renders booking-question field labels via React's dangerouslySetInnerHTML without sanitizing or escaping user…

  • CVE-2024-58353HigJul 23, 2026
    risk 0.51cvss 8.9epss 0.00

    Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/). Booking question (form field) labels are rendered via React's dangerouslySetInnerHTML without proper input…

  • CVE-2026-9303MedMay 23, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted…

  • CVE-2026-16624CriJul 22, 2026
    risk 0.00cvss 9.6epss 0.00

    Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally…

  • CVE-2026-63768MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigned state parameter and onErrorReturnTo…