{"api_version":"v1","generated_at":"2026-10-07T14:05:00+00:00","product":{"cve_count":9,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-calcom-cal-diy-e2037bea1810","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"cal.diy","next_cursor":null,"observations":[{"affected":"cal.diy: 6.0, 6.1, 6.2.0","affected_versions_present":true,"cve_id":"CVE-2026-104054","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-104054","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-02T19:52:48.259Z","patch_url":"","primary_source":"","published":"2026-10-02T02:00:11.876Z"},{"affected":"cal.diy: < 5.9.9","affected_versions_present":true,"cve_id":"CVE-2025-71389","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-71389","fixed":"cal.diy: 5.9.9","last_modified":"2026-07-28T01:48:14.200Z","patch_url":"https://github.com/calcom/cal.diy/security/advisories/GHSA-qjx2-5xqp-cpf4","primary_source":"","published":"2026-07-23T21:16:44.870Z"},{"affected":"\u2264 4.7.15","affected_versions_present":true,"cve_id":"CVE-2024-58355","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-58355","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-28T01:47:45.864Z","patch_url":"","primary_source":"","published":"2026-07-23T21:16:44.180Z"},{"affected":"See the vendor and CVE records for the affected range.","affected_versions_present":false,"cve_id":"CVE-2024-58354","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-58354","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-24T21:35:07.962Z","patch_url":"","primary_source":"","published":"2026-07-23T21:16:43.545Z"},{"affected":"\u2264 4.7.15","affected_versions_present":true,"cve_id":"CVE-2024-58353","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-58353","fixed":"4.7.16.","last_modified":"2026-07-28T01:47:45.196Z","patch_url":"https://github.com/calcom/cal.diy/security/advisories/GHSA-vgj7-76cw-h6f8","primary_source":"","published":"2026-07-23T21:16:42.870Z"},{"affected":"cal.diy: \u2264 6.2.0","affected_versions_present":true,"cve_id":"CVE-2026-63768","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63768","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-17T17:54:33.851Z","patch_url":"","primary_source":"","published":"2026-07-20T19:08:21.751Z"},{"affected":"4.9.0; 4.9.1; 4.9.2; 4.9.3; 4.9.4","affected_versions_present":true,"cve_id":"CVE-2026-9349","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-9349","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T13:37:06.325Z","patch_url":"","primary_source":"","published":"2026-05-24T02:30:11.039Z"},{"affected":"4.9.0; 4.9.1; 4.9.2; 4.9.3; 4.9.4","affected_versions_present":true,"cve_id":"CVE-2026-9304","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-9304","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T13:57:25.677Z","patch_url":"","primary_source":"","published":"2026-05-23T13:45:08.165Z"},{"affected":"4.9.0; 4.9.1; 4.9.2; 4.9.3; 4.9.4","affected_versions_present":true,"cve_id":"CVE-2026-9303","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-9303","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-26T18:41:50.216Z","patch_url":"","primary_source":"","published":"2026-05-23T13:30:10.147Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"calcom"}}
