CVE-2024-58355
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
23/07/2026
Last modified:
30/07/2026
Description
Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/) renders booking-question field labels via React's dangerouslySetInnerHTML without sanitizing or escaping user input. An attacker who can create an event type with a malicious booking-question label can inject arbitrary HTML/JavaScript that executes when a victim opens the crafted booking URL. The issue is fixed in v4.7.16.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
8.90
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/calcom/cal.diy/commit/00689fda0a30b8f933c096f02c1fe092a4206def
- https://github.com/calcom/cal.diy/security/advisories/GHSA-vgj7-76cw-h6f8
- https://www.vulncheck.com/advisories/cal-com-through-cross-site-scripting-via-booking-questions-2
- https://github.com/calcom/cal.diy/security/advisories/GHSA-vgj7-76cw-h6f8



