Cal.com (repository calcom/cal.diy) in versions <= 4.7.15...
Critical severity
Unreviewed
Published
Jul 24, 2026
to the GitHub Advisory Database
•
Updated Jul 24, 2026
Description
Published by the National Vulnerability Database
Jul 23, 2026
Published to the GitHub Advisory Database
Jul 24, 2026
Last updated
Jul 24, 2026
Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/). Booking question (form field) labels are rendered via React's dangerouslySetInnerHTML without proper input sanitization or CSP, so an attacker who can create an event type with a malicious booking question label can inject arbitrary HTML/JavaScript that executes when a victim visits the booking view URL. Self-hosted instances with open registration are particularly at risk. The issue is fixed in version 4.7.16.
References