In Documize in affected versions a high severity vulnerability CVE-2026-71234 was detected. This vulnerability allows an attacker to download attachments without proper authentication. To address this issue, users should upgrade Documize to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-71234.
Read more ProductivityIn Cal.com OSS a critical severity vulnerability CVE-2026-16624 was detected. This vulnerability allows any authenticated user to steal sensitive booking data, including attendee PII and video-call passwords, from any team. To address this issue, users should upgrade Cal to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-16624.
Read more ProductivityIn Cal versions 4.7.15 and earlier a high severity vulnerability CVE-2024-58353 was detected. This vulnerability allows an attacker to inject arbitrary HTML or JavaScript. To address this issue, users should upgrade Cal to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-58353.
Read more ProductivityIn Cal a critical severity vulnerability CVE-2026-16624 was detected. This vulnerability allows any authenticated user to create a webhook on any team and steal booking data. To address this issue, users should upgrade Cal to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-16624.
Read more ProductivityIn Cal.com versions up to and including 1.0.0 a medium severity vulnerability CVE-2025-31604 was detected. This vulnerability allows attackers to execute stored cross-site scripting (XSS) attacks by improperly neutralizing script-related HTML tags in a web page. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-31604.
Read more ProductivityIn ONLYOFFICE Docs Plugin for WordPress versions up to and including 2.0.0 a medium severity vulnerability CVE-2024-11450 was detected. This vulnerability allows attackers with contributor-level access or higher to inject arbitrary web scripts into pages via the ‘onlyoffice’ shortcode. These scripts execute whenever a user accesses an injected page. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-11450.
Read more Productivity