Cross-Site Scripting Vulnerability in Cal.com by Cal
CVE-2024-58353

9.3CRITICAL

Key Information:

Vendor

Calcom

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2024-58353?

The cross-site scripting vulnerability in Cal.com versions up to 4.7.15 allows attackers to exploit the single booking view. By using React's dangerouslySetInnerHTML concept without appropriate input sanitization or content security policies, an attacker can introduce harmful HTML or JavaScript through malicious booking question labels. This poses a significant risk, especially for self-hosted instances that permit open user registrations, as unwary users visiting the compromised booking view URL may inadvertently execute the injected code. The issue has been rectified in version 4.7.16.

Affected Version(s)

cal.diy 0 <= 4.7.15

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

xyzeva
.