VYPR
Vendor

Cal

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-23478CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.00

    Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This…

  • CVE-2025-66489CriDec 3, 2025
    risk 0.64cvss 9.8epss 0.01

    Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic…

  • CVE-2023-37919MedJul 25, 2023
    risk 0.42cvss 6.5epss 0.00

    Cal.com is open-source scheduling software. A vulnerability allows active sessions associated with an account to remain active even after enabling 2FA. When activating 2FA on a Cal.com account that is logged in on two or more devices, the account stays logged in on the other…