Stored XSS Vulnerability in Cal.com by Cal.com
CVE-2025-31604
6.5MEDIUM
What is CVE-2025-31604?
Cal.com has a stored Cross-Site Scripting (XSS) vulnerability that arises from the improper neutralization of script-related HTML tags within web pages. This flaw allows attackers to inject malicious scripts that can execute in the context of users accessing the affected application, potentially compromising data integrity or exposing sensitive information. The issue has been identified in versions up to and including 1.0.0, posing a significant risk to user environments.
Affected Version(s)
Cal.com 0 <= 1.0.0
