CVE-2025-66546
LOWNextcloud Calendar <4.7.19, 5.5.6, 6.0.1 - Info Disclosure
Title source: llmDescription
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.
References (4)
Core 4
Core References
Patch, Vendor Advisory x_refsource_confirm
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7x2j-2674-fj95
Issue Tracking x_refsource_misc
https://github.com/nextcloud/calendar/pull/7537
Patch x_refsource_misc
https://github.com/nextcloud/calendar/commit/f41650c3681fc4a4130eb883f5c0899c011326b3
Issue Tracking, Vendor Advisory x_refsource_misc
https://hackerone.com/reports/3275810
Scores
CVSS v3
3.3
EPSS
0.0001
EPSS Percentile
0.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (2)
nextcloud/calendar
6.0.0 (7 CPE variants)
nextcloud/calendar
4.0.0 - 4.7.19
Published
Dec 05, 2025
Tracked Since
Feb 18, 2026