Stored Cross-Site Scripting Vulnerability in Cal.com Cal.diy Product
CVE-2026-57858

9.3CRITICAL

Key Information:

Vendor

Cal.com

Vendor
CVE Published:
12 August 2026

What is CVE-2026-57858?

The Cal.com Cal.diy product, specifically versions 2.1.1 through 6.2.0, has a stored cross-site scripting (XSS) vulnerability found within the BookingPageTagManager component. This issue enables authenticated event owners to inject malicious JavaScript via an unvalidated analytics tracking ID. When exploited, the entered payload can close the inline script string literal to execute arbitrary scripts in the browser of anyone visiting the public booking page. This could lead to various malicious activities such as session cookie theft, unauthorized requests, and even allow attackers to propagate further by utilizing cross-site request forgery (CSRF) vulnerabilities, making it possible to embed malicious payloads into additional events.

Affected Version(s)

Cal.com Self-Hosted (Cal.diy) 2.1.1 <= 6.2.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ashton Richards
.