{"id":"CVE-2026-57858","title":"Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analyt…","summary":"Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analyt…","severity":"high","cvss":8.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L","cwe":["CWE-79"],"published":"2026-08-12","updated":"2026-09-24","sourceUpdated":"2026-09-24T20:06:30.133","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57858","references":[{"url":"https://ashtonr.com/blog/cve-2026-57858/","label":"disclosure@vulncheck.com"},{"url":"https://github.com/calcom/cal.com","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/cal-com-cal-diy-stored-xss-via-bookingpagetagmanager-analytics-tracking-id","label":"disclosure@vulncheck.com"},{"url":"https://ashtonr.com/blog/cve-2026-57858/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.00415,"epssPercentile":0.33097,"exploits":{"github":1,"githubRepos":["https://github.com/zylideum/CVE-2026-57858"],"checkedAt":"2026-09-24T20:52:15.407Z"},"exploitAvailable":true,"ingestedAt":"2026-09-24T20:51:40.198Z","slug":"CVE-2026-57858","body":"## Overview\n\nCal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":49,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}