CVE-2025-66546
LOWNextcloud Calendar <4.7.19, 5.5.6, 6.0.1 - Info Disclosure
Title source: llmDescription
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.
Scores
CVSS v3
3.3
EPSS
0.0001
EPSS Percentile
0.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-639
Status
published
Affected Products (8)
nextcloud/calendar
< 4.7.19
nextcloud/calendar
nextcloud/calendar
nextcloud/calendar
nextcloud/calendar
nextcloud/calendar
nextcloud/calendar
nextcloud/calendar
Timeline
Published
Dec 05, 2025
Tracked Since
Feb 18, 2026