cal
Security Risk Profile
72
/100
highSecurity Risk Score
Comprehensive risk assessment based on 4 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 27, 2023 to present
4
Total CVEs
3
Critical+High
0
Exploited
2
Unpatched
Threat Assessment
Avg CVSS
8.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
72/100
high
Severity Distribution
Critical
2High
1Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
No CWE data available
Most Affected Products
1. cal cal.com4
2. npm/cal1
3. Cal.com Cal.com1
Recent Vulnerabilities
See more →CVE-2026-23478
CVSS 10.0EPSS 0%critical
Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback
1/13/2026🔧 No Patch
CVE-2025-66489
CVSS 9.9critical
Cal.com Authentication Bypass via bad TOTP + password checks
12/3/2025🔧 No Patch
CVE-2023-37919
CVSS 6.5medium
Cal.com not expiring old sessions after enabling 2FA
7/25/2023🔧 No Patch
CVE-2023-1647
CVSS 8.8high
Improper Access Control in calcom/cal.com
3/27/2023
Monitor cal in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.