← Back

CVE-2025-66546

nvd nist
Published: Dec 5, 2025Modified: Jun 17, 2026

JSON object

Loading...
3.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.8 / Impact: 1.4
Source: security-advisories@github.com (Secondary)

Description

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.

Affected (9)

Products: Nextcloud: Calendar
1 product
Calendar
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
From 4.0.0 to 4.7.19
From 5.0.0 to 5.5.6
Version 6.0.0
Version 6.0.0 rc1
Version 6.0.0 rc2
Version 6.0.0 rc3
Version 6.0.0 rc4
Version 6.0.0 rc5
Version 6.0.0 rc6

References (4)

Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
Issue TrackingVendor Advisory

Timeline

No history available yet.