Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.
2025-12-05T17:16:05.163
2025-12-09T16:36:01.357
Analyzed
CVSSv3.1: 3.3 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | nextcloud | calendar | < 4.7.19 | Yes |
| Application | nextcloud | calendar | < 5.5.6 | Yes |
| Application | nextcloud | calendar | 6.0.0 | Yes |
| Application | nextcloud | calendar | 6.0.0 | Yes |
| Application | nextcloud | calendar | 6.0.0 | Yes |
| Application | nextcloud | calendar | 6.0.0 | Yes |
| Application | nextcloud | calendar | 6.0.0 | Yes |
| Application | nextcloud | calendar | 6.0.0 | Yes |
| Application | nextcloud | calendar | 6.0.0 | Yes |