luxsoft CVE Vulnerabilities & CVE List (10)

Products (CPE): — CVEs: 10

luxsoft vulnerability overview

Aggregates CVE and security vulnerability intelligence across all luxsoft-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk sql injection, vendor risk cross-site scripting, and vendor risk path handling, with potential vendor impact data exposure across vendor surface software deployment use cases.

Vulnerability distribution trend (last 24 months)

Showing 110 of 10 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-25224 The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained. [email protected] 7.5 0.04% 2025-02-18 2025-09-15
CVE-2025-25223 The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained. [email protected] 5.3 0.04% 2025-02-18 2025-09-15
CVE-2025-25222 The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrieve.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved. [email protected] 9.8 0.03% 2025-02-18 2025-09-15
CVE-2025-25221 The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved. [email protected] 9.8 0.03% 2025-02-18 2025-09-15
CVE-2023-47175 Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the product. [email protected] 6.1 0.11% 2023-11-20 2024-11-21
CVE-2023-46700 SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and obtain or alter information stored in the database. [email protected] 9.8 0.40% 2023-11-20 2024-11-21
CVE-2023-39939 SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it. [email protected] 9.1 0.18% 2023-08-21 2024-11-21
CVE-2023-39543 Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product. [email protected] 6.1 0.27% 2023-08-21 2024-11-21
CVE-2021-45915 In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator. [email protected] 9.8 1.20% 2022-05-24 2024-11-21
CVE-2021-45914 In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator. [email protected] 9.8 1.20% 2022-05-24 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence