PT-2026-64179 · Cal.Com · Cal.Com

·

CVE-2024-58353

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions Cal.com versions prior to 4.7.16
Description Cross-site scripting (XSS) occurs on the publicly accessible single booking view endpoint '/booking/'. The application uses React's dangerouslySetInnerHTML to render booking question form field labels without proper input sanitization or a Content Security Policy (CSP). This allows an attacker to create an event type with a malicious label to inject arbitrary HTML or JavaScript, which executes when a victim visits the booking URL. Self-hosted instances with open registration are especially susceptible.
Recommendations Update to version 4.7.16.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58353
GHSA-VGJ7-76CW-H6F8

Affected Products

Cal.Com