Calendar
Vendor:
First CVE: Jul 5, 2018 · Active for 8 years
10
Total CVEs
More Total CVEs than 88% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Calendar over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 5, 2018
8 years ago
Most Recent CVE
Jun 1, 2026
53 days ago
CVE Severity & Scoring
Calendar10 CVEs
10%
80%
10%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumCritical
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (70.0%)
Unknown0 (0.0%)
Required3 (30.0%)
Privileges Required
Low7 (70.0%)
High1 (10.0%)
None2 (20.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24838CRITICAL Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sani | Apr 11, 2022 | 9.8 | 48 | NO | NO |
CVE-2026-45286MEDIUM Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users on the same | Jun 1, 2026 | 4.3 | 22 | NO | NO |
CVE-2025-66511MEDIUM Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for meeting proposals using a hash function, allowing an attacker | Dec 5, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-66550MEDIUM Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download lin | Dec 5, 2025 | 5.7 | 21 | NO | NO |
CVE-2023-48308MEDIUM Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar ap | Dec 22, 2023 | 6.5 | 20 | NO | NO |
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the a | Dec 5, 2025 | 3.3 | 17 | NO | NO |
CVE-2018-3763MEDIUM In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing | Jul 5, 2018 | 4.8 | 17 | NO | NO |
CVE-2023-33183MEDIUM Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is | May 30, 2023 | 4.3 | 16 | NO | NO |
CVE-2024-37316MEDIUM Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when click | Jun 14, 2024 | 4.6 | 15 | NO | NO |
CVE-2023-45150MEDIUM Nextcloud calendar is a calendar app for the Nextcloud server platform. Due to missing precondition checks the server was trying to validate strings of any length as email addresse | Oct 16, 2023 | 4.3 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Calendar
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.0.0 | 1 | 3.3 | 0.1% | 0 | 0 |
| 1.6.0 | 1 | 4.8 | 0.6% | 0 | 0 |