CVE-2025-31604
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 80
Summary
CVE-2025-31604 is a Stored Cross-Site Scripting (XSS) vulnerability affecting Cal.com. The flaw, which is a type of Basic XSS, arises from Cal.com's failure to properly neutralize script-related HTML tags in user-supplied data. This issue enables an attacker to inject malicious scripts into a web page viewed by other users, potentially leading to theft of user data or unauthorized account access. Affected versions of Cal.com span from n/a to 1.0.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.