Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Cal.com Cal.com cal-com allows Stored XSS.This issue affects Cal.com: from n/a through <= 1.0.0.
Published: 2025-03-31
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Cal.com WordPress plugin is vulnerable to stored cross site scripting, allowing an attacker to inject malicious JavaScript that is rendered in the browsers of users who view content managed by the plugin. An attacker exploiting this flaw can execute arbitrary code in the victim’s browser, potentially stealing session cookies, defacing site interfaces, or hijacking user interactions. The weakness is a classic example of improper input sanitization, identified as CWE‑80.

Affected Systems

The vulnerability affects all installations of the Cal.com plugin with version 1.0.0 or earlier. This includes every site that has the plugin installed without updating to a later release that contains the fix.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.5, reflecting a medium severity threat. The EPSS score is below 1%, indicating a low estimated likelihood of exploitation at present. The flaw is not listed in the CISA KEV catalog, but the stored nature of the XSS means that any user who can submit or edit content through the affected plugin is at risk. The most likely attack vector is user‑generated content that is saved to the database and rendered without proper escaping. Due to the low EPSS, the risk is moderate, but the impact on user browsers warrants prompt remediation.

Generated by OpenCVE AI on May 1, 2026 at 12:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Cal.com plugin to the latest supported version that resolves the XSS flaw.
  • If an update is not immediately available, disable or remove the plugin to eliminate the attack surface.
  • Apply input validation or output encoding to any custom fields that are still exposed, ensuring that script tags are neutralized.
  • Monitor site activity for unexpected script injection attempts.

Generated by OpenCVE AI on May 1, 2026 at 12:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8796 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Cal.com Cal.com allows Stored XSS. This issue affects Cal.com: from n/a through 1.0.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Cal.com Cal.com allows Stored XSS. This issue affects Cal.com: from n/a through 1.0.0. Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Cal.com Cal.com cal-com allows Stored XSS.This issue affects Cal.com: from n/a through <= 1.0.0.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Mon, 31 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Cal.com Cal.com allows Stored XSS. This issue affects Cal.com: from n/a through 1.0.0.
Title WordPress Cal.com plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:10.037Z

Reserved: 2025-03-31T10:06:10.340Z

Link: CVE-2025-31604

cve-icon Vulnrichment

Updated: 2025-03-31T15:46:13.256Z

cve-icon NVD

Status : Deferred

Published: 2025-03-31T13:15:54.273

Modified: 2026-04-23T15:28:03.550

Link: CVE-2025-31604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:15:17Z

Weaknesses