---
id: CVE-2026-57858
title: >-
  Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site
  scripting vulnerability in the BookingPageTagManager component that allows
  authenticated event owners to inject arbitrary JavaScript by supplying a
  malicious analyt…
summary: >-
  Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site
  scripting vulnerability in the BookingPageTagManager component that allows
  authenticated event owners to inject arbitrary JavaScript by supplying a
  malicious analyt…
severity: high
cvss: 8.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L'
cwe:
  - CWE-79
published: '2026-08-12'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:06:30.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57858'
references:
  - url: 'https://ashtonr.com/blog/cve-2026-57858/'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/calcom/cal.com'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/cal-com-cal-diy-stored-xss-via-bookingpagetagmanager-analytics-tracking-id
    label: disclosure@vulncheck.com
  - url: 'https://ashtonr.com/blog/cve-2026-57858/'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.0037
epssPercentile: 0.28323
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/zylideum/CVE-2026-57858'
  checkedAt: '2026-09-27T10:33:53.057Z'
exploitAvailable: true
ingestedAt: '2026-09-24T20:51:40.198Z'
---

## Overview

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
