CVE-2023-46700: Luxsoft Luxcal Web Calendar

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and obtain or alter information stored in the database.

Affected products

  • Luxsoft Luxcal Web Calendar: before 5.2.4l (fixed in 5.2.4l); before 5.2.4m (fixed in 5.2.4m)

Published 2023-11-20. Last modified 2026-06-17.