VYPR

Luxcal

by Luxsoft

CVEs (3)

  • CVE-2021-45915CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.02

    In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.

  • CVE-2021-45914CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.02

    In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.

  • CVE-2026-36989MedSep 13, 2026
    risk 0.38cvss 5.8epss 0.00

    A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.