Impact
Cal.com (calcom/cal.diy) through version 4.7.15 includes a stored cross‑site scripting flaw in the single‑booking view. The application renders booking‑question field labels with React’s dangerouslySetInnerHTML without sanitizing or escaping user‑supplied input. An attacker who can create an event type with a malicious booking‑question label can embed arbitrary HTML or JavaScript that executes automatically when a user opens the crafted booking URL. The injected code runs in the victim’s browser and can be used for session hijacking, data theft, or other client‑side attacks.
Affected Systems
The vulnerability affects Cal.com’s self‑hosted product “Cal.com DIY”, identified by the CNA vendor/product calcom:cal.diy. All releases up to and including 4.7.15 are impacted; the fix is distributed in version 4.7.16.
Risk and Exploitability
The CVSS score of 9.3 marks this flaw as high‑severity, and the EPSS indicates a very low probability of exploitation at present (under 1 %). Nevertheless, the flaw is listed as a high‑severity stored XSS and not currently in the CISA KEV catalog. An attacker does not need privileged access to the system; they only need the ability to create a custom event type, after which any user who visits the booking link will be exposed to the injected script. The impact is limited to the scope of the victim’s browser session, but it enables a range of downstream client‑side attacks.
OpenCVE Enrichment