CVE-2023-39939: Luxsoft Luxcal Web Calendar

Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.

SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.

Affected products

  • Luxsoft Luxcal Web Calendar: before 5.2.3m (fixed in 5.2.3m); before 5.2.3l (fixed in 5.2.3l)

Published 2023-08-21. Last modified 2026-06-17.