CVE-2026-57858
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events.
- Affected products
- Cal.Diy
- CVSS 4.0
- 9.3 CRITICAL
- CVSS 3.1
- 8.9 HIGH
- EPSS
- 0.4% (35th percentile)
- Weakness
- CWE-79
- NVD status
- Received
- Published
- 2026-08-12
CVE-2026-57858 at NVD
1 known exploit for CVE-2026-57858
Proof-of-concept code and exploit modules indexed by Sploitus