cal records
4 published records for vendor cal.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control1
- CWE-303 Incorrect Implementation of Authentication Algorithm1
- CWE-602 Client-Side Enforcement of Server-Side Security1
- CWE-613 Insufficient Session Expiration1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-23478No exploit | Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callbackcal · cal.com · CWE-602 | Critical10.0 | — | 0.5% | Jan 13, 2026 |
39Monitor | CVE-2025-66489No exploit | Cal.com Authentication Bypass via bad TOTP + password checkscal · cal.com · CWE-303 | Critical9.9 | — | 0.8% | Dec 3, 2025 |
35Monitor | CVE-2023-1647No exploit | Improper Access Control in calcom/cal.comcal · cal.com · CWE-284 | High8.8 | — | 0.8% | Mar 26, 2023 |
21Monitor | CVE-2023-37919No exploit | Cal.com not expiring old sessions after enabling 2FAcal · cal.com · CWE-613 | Medium5.4 | — | 0.3% | Jul 25, 2023 |
- CVE-2026-2347840Plan
Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback
CriticalCVSS 10.0No exploitEPSS 0%cal · cal.comJan 13, 2026
- CVE-2025-6648939Monitor
Cal.com Authentication Bypass via bad TOTP + password checks
CriticalCVSS 9.9No exploitEPSS 1%cal · cal.comDec 3, 2025
- CVE-2023-164735Monitor
Improper Access Control in calcom/cal.com
HighCVSS 8.8No exploitEPSS 1%cal · cal.comMar 26, 2023
- CVE-2023-3791921Monitor
Cal.com not expiring old sessions after enabling 2FA
MediumCVSS 5.4No exploitEPSS 0%cal · cal.comJul 25, 2023