Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nextcloud:calendar:*:*:*:*:*:*:*:* cpe:2.3:a:nextcloud:calendar:6.0.0:-:*:*:*:*:*:* cpe:2.3:a:nextcloud:calendar:6.0.0:rc1:*:*:*:*:*:* cpe:2.3:a:nextcloud:calendar:6.0.0:rc2:*:*:*:*:*:* cpe:2.3:a:nextcloud:calendar:6.0.0:rc3:*:*:*:*:*:* cpe:2.3:a:nextcloud:calendar:6.0.0:rc4:*:*:*:*:*:* cpe:2.3:a:nextcloud:calendar:6.0.0:rc5:*:*:*:*:*:* cpe:2.3:a:nextcloud:calendar:6.0.0:rc6:*:*:*:*:*:* |
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextcloud
Nextcloud calendar |
|
| Vendors & Products |
Nextcloud
Nextcloud calendar |
Fri, 05 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1. | |
| Title | Nextcloud Calendar app allowed booking appointments without the generated token | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-05T16:49:46.553Z
Updated: 2025-12-05T18:32:44.271Z
Reserved: 2025-12-04T15:52:26.549Z
Link: CVE-2025-66546
Updated: 2025-12-05T18:32:34.528Z
Status : Analyzed
Published: 2025-12-05T17:16:05.163
Modified: 2025-12-09T16:36:01.357
Link: CVE-2025-66546
No data.