CVE Feed

    Dashboard / CVE / CVE-2026-57858

    CVE-2026-57858

    Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events.

    Published:Aug 12, 2026
    Last Modified:Aug 13, 2026
    EPS:Aug 12, 2026
    EPSS Score:0.00415
    CVSS Score:8.9

    Affected Products

    Vendor
    Cal.com
    Product
    Cal.com Self-hosted (cal.diy)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High