VendorsNextcloudcalendarany version
Vulnerabilities

Nextcloud Calendar any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2022-24838
Command Injection in Appointment Emails for Nextcloud Calendar
Published 2022-04-11 · Modified
9.8EPSS 0.330
CVE-2023-48308
Calendar app returns full stacktrace when an error happens while editing appointment
Published 2023-12-21 · Modified
6.5EPSS 0.005
CVE-2025-66511
Nextcloud Calendar app used predictable proposal participant tokens
Published 2025-12-05 · Analyzed
6.5EPSS 0.003
CVE-2025-66550
Nextcloud Calendar attachments of local files are offered to downloaded
Published 2025-12-05 · Analyzed
5.7EPSS 0.003
CVE-2018-3763
In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins.
Published 2018-07-05 · Modified
4.8EPSS 0.006
CVE-2024-37316
Nextcloud Calendar's event create can create attachments that link to other websites
Published 2024-06-14 · Modified
4.6EPSS 0.004
CVE-2023-33183
Error in calendar when booking an appointment reveals the full path of the website
Published 2023-05-30 · Modified
4.3EPSS 0.004
CVE-2023-45150
Inviting excessive long email addresses to a calendar event makes the Nextcloud server unresponsive
Published 2023-10-16 · Modified
4.3EPSS 0.004
CVE-2026-45286
Nextcloud: Calendar app leaked user identifiers via attendee suggestion endpoint
Published 2026-06-01 · Analyzed
4.3EPSS 0.003
CVE-2025-66546
Nextcloud Calendar app allowed booking appointments without the generated token
Published 2025-12-05 · Analyzed
3.3EPSS 0.001