CVE-2025-25222: Luxsoft Luxcal Web Calendar

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrieve.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.

Affected products

  • Luxsoft Luxcal Web Calendar: before 5.3.3l (fixed in 5.3.3l); before 5.3.3m (fixed in 5.3.3m)

Published 2025-02-18. Last modified 2026-06-17.