Filtered by vendor Luxsoft Subscriptions
Filtered by product Luxcal Web Calendar Subscriptions
Total 6 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-25221 1 Luxsoft 2 Luxcal, Luxcal Web Calendar 2025-07-21 N/A
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.
CVE-2025-25224 1 Luxsoft 1 Luxcal Web Calendar 2025-07-13 N/A
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.
CVE-2023-47175 1 Luxsoft 1 Luxcal Web Calendar 2024-11-21 6.1 Medium
Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the product.
CVE-2023-46700 1 Luxsoft 1 Luxcal Web Calendar 2024-11-21 9.8 Critical
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and obtain or alter information stored in the database.
CVE-2023-39939 2 Luxcal, Luxsoft 2 Web Calendar, Luxcal Web Calendar 2024-11-21 9.1 Critical
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.
CVE-2023-39543 1 Luxsoft 1 Luxcal Web Calendar 2024-11-21 6.1 Medium
Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product.