Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-66546


Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.


Published

2025-12-05T17:16:05.163

Last Modified

2025-12-09T16:36:01.357

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 3.3 (LOW)

Weaknesses
  • Type: Secondary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud calendar < 4.7.19 Yes
Application nextcloud calendar < 5.5.6 Yes
Application nextcloud calendar 6.0.0 Yes
Application nextcloud calendar 6.0.0 Yes
Application nextcloud calendar 6.0.0 Yes
Application nextcloud calendar 6.0.0 Yes
Application nextcloud calendar 6.0.0 Yes
Application nextcloud calendar 6.0.0 Yes
Application nextcloud calendar 6.0.0 Yes

References