CVE-2026-36989: Luxsoft Luxcal Web Calendar

Medium severity, CVSS 5.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.

Affected products

  • Luxsoft Luxcal Web Calendar: up to and including 5.3.4L

Published 2026-09-13. Last modified 2026-09-22.