VendorsCalcal.comall versions
Vulnerabilities

Cal Cal.com

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2026-23478
Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback
Published 2026-01-13 · Analyzed
10.0EPSS 0.005
CVE-2025-66489
Cal.com Authentication Bypass via bad TOTP + password checks
Published 2025-12-03 · Analyzed
9.9EPSS 0.008
CVE-2023-1647
Improper Access Control in calcom/cal.com
Published 2023-03-27 · Modified
8.8EPSS 0.008
CVE-2023-37919
Cal.com not expiring old sessions after enabling 2FA
Published 2023-07-25 · Modified
6.5EPSS 0.003