FR
live
High CVSS 8.9

CVE-2026-57858

NVD analysis in progress

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events.

What this means

Exposure
Exploitable remotely over the network and with an ordinary user account — but only if a user opens booby-trapped content.
Impact
An attacker can read sensitive data, modify or destroy data and degrade the service. The impact spreads beyond the vulnerable component into other parts of the system.
Weakness
Attacker-supplied script runs in other users’ browsers (cross-site scripting).
Likelihood
Its EPSS score stays low: nothing points to imminent exploitation, which is no reason to leave it unpatched.

What to doFold into the next patch cycle.

Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.

Published
12 August 2026
CVSS
8.9 (v3.1) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
EPSS
0.37% probability of exploitation within 30 days · above 30% of all CVEs
Weakness
CWE-79
Sources
nvd
References

Type at least two characters.

navigate open esc dismiss