CVE-2025-25223: Luxsoft Luxcal Web Calendar

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.

Affected products

  • Luxsoft Luxcal Web Calendar: before 5.3.3l (fixed in 5.3.3l); before 5.3.3m (fixed in 5.3.3m)

Published 2025-02-18. Last modified 2026-06-17.