Sploitus

CVE-2026-57858

1 known exploit for CVE-2026-57858

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events.

Affected products
Cal.Diy
CVSS 4.0
9.3 CRITICAL
CVSS 3.1
8.9 HIGH
EPSS
0.4% (35th percentile)
Weakness
CWE-79
NVD status
Received
Published
2026-08-12
CVE-2026-57858 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-57858

Proof-of-concept code and exploit modules indexed by Sploitus