CVE-2025-66546
05.12.2025, 17:16
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.Enginsight
| Vendor | Product | Version |
|---|---|---|
| nextcloud | calendar | 4.0.0 ≤ 𝑥 < 4.7.19 |
| nextcloud | calendar | 5.0.0 ≤ 𝑥 < 5.5.6 |
| nextcloud | calendar | 6.0.0 |
| nextcloud | calendar | 6.0.0:rc1 |
| nextcloud | calendar | 6.0.0:rc2 |
| nextcloud | calendar | 6.0.0:rc3 |
| nextcloud | calendar | 6.0.0:rc4 |
| nextcloud | calendar | 6.0.0:rc5 |
| nextcloud | calendar | 6.0.0:rc6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration