Stored Cross-Site Scripting Vulnerability in Cal.com by Cal.com
CVE-2024-58355

9.3CRITICAL

Key Information:

Vendor

Calcom

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2024-58355?

Cal.com versions up to 4.7.15 are vulnerable to a stored cross-site scripting (XSS) flaw. This issue arises from the 'booking-question' field labels being rendered unsanitized via React's dangerouslySetInnerHTML, allowing an attacker to inject malicious JavaScript or HTML into the application. When a victim accesses a specially crafted booking URL, the injected code can execute in their browser, potentially compromising user data or leading to other malicious actions. The vulnerability has been addressed in version 4.7.16.

Affected Version(s)

cal.diy 0 <= 4.7.15

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

xyzeva
.