CVE-2025-66546: Nextcloud Calendar
Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.
Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.
Affected products
- Nextcloud Calendar: from 4.0.0, before 4.7.19 (fixed in 4.7.19); from 5.0.0, before 5.5.6 (fixed in 5.5.6); version 6.0.0 only
Published 2025-12-05. Last modified 2026-06-17.