CVE-2017-9072: Calendarxp Flatcalendarxp

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

Two CalendarXP products have XSS in common parts of HTML files. CalendarXP FlatCalendarXP through 9.9.290 has XSS in iflateng.htm and nflateng.htm. CalendarXP PopCalendarXP through 9.8.308 has XSS in ipopeng.htm and npopeng.htm.

Affected products

  • Calendarxp Flatcalendarxp: up to and including 9.9.290
  • Calendarxp Popcalendarxp: up to and including 9.8.308

Published 2017-05-18. Last modified 2026-06-17.