๐Ÿ” CVE Alert

CVE-2026-57858

HIGH 8.9

Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID

CVSS Score
8.9
EPSS Score
0.0%
EPSS Percentile
0th

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events.

CWE CWE-79
Vendor cal.com
Product cal.com self-hosted (cal.diy)
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for cal.com cal.com self-hosted (cal.diy)

Be the first to know when new high vulnerabilities affecting cal.com cal.com self-hosted (cal.diy) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

Cal.com / Cal.com Self-Hosted (Cal.diy)
2.1.1 โ‰ค 6.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/calcom/cal.com ashtonr.com: https://ashtonr.com/blog/cve-2026-57858/ vulncheck.com: https://www.vulncheck.com/advisories/cal-com-cal-diy-stored-xss-via-bookingpagetagmanager-analytics-tracking-id

Credits

Ashton Richards