Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

calcom — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting calcom. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Calcom provides scheduling and booking solutions primarily used for appointment management across various industries. Historically, vulnerabilities have included stored cross-site scripting (XSS) and remote code execution (RCE) flaws, often stemming from improper input validation and insecure direct object references. The platform has faced security incidents where unauthorized access could lead to data exposure or system compromise. Security characteristics reveal a pattern of vulnerabilities affecting both frontend and backend components, with privilege escalation risks identified in administrative interfaces. While no major public breaches have been widely documented, the consistent presence of multiple CVEs indicates ongoing security challenges that require robust patch management and secure coding practices.

CVE ID Title CVSS Severity Published
CVE-2025-71389 Cal.com before 5.9.9 Remote Code Execution via RSC — cal.diy CWE-94 10.0 Critical 2026-07-23
CVE-2024-58355 Cal.com through 4.7.15 Cross-Site Scripting via booking questions — cal.diy CWE-80 8.9 High 2026-07-23
CVE-2024-58354 cal.com Repository Takeover via pull_request_target Workflow — cal.diy CWE-77 9.9 Critical 2026-07-23
CVE-2024-58353 Cal.com through 4.7.15 Cross-Site Scripting via booking questions — cal.diy CWE-80 8.9 High 2026-07-23
CVE-2026-63768 cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State — cal.diy CWE-601 4.3 Medium 2026-07-20
CVE-2026-9349 calcom cal.diy Generic React API bookings-single-view.getServerSideProps.tsx getServerSideProps information disclosure — cal.diy CWE-200 5.3 Medium 2026-05-24
CVE-2026-9304 calcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery — cal.diy CWE-918 5.0 Medium 2026-05-23
CVE-2026-9303 calcom cal.diy cross-site request forgery — cal.diy CWE-352 4.3 Medium 2026-05-23
CVE-2026-23478 Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback — cal.com CWE-602 9.8AI Critical AI 2026-01-13
CVE-2025-66489 Cal.com Authentication Bypass via bad TOTP + password checks — cal.com CWE-303 9.8AI Critical AI 2025-12-03
CVE-2023-37919 Cal.com not expiring old sessions after enabling 2FA — cal.com CWE-613 6.5 Medium 2023-07-25
CVE-2023-1647 Improper Access Control in calcom/cal.com — calcom/cal.com CWE-284 8.8 High 2023-03-27

This page lists every published CVE security advisory associated with calcom. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.