CVE-2026-36989: Luxsoft Luxcal Web Calendar
Medium severity, CVSS 5.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.
Affected products
- Luxsoft Luxcal Web Calendar: up to and including 5.3.4L
Published 2026-09-13. Last modified 2026-09-22.