PT-2026-90960 · Luxsoft · Luxcal Web Calendar

CVE-2026-36989

·

Published

2026-09-13

·

Updated

2026-09-15

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions LuxSoft LuxCal versions prior to 5.3.4L
Description A SQL Injection issue exists where an attacker can interfere with the queries that an application makes to its database. This occurs via the 'rssfeed.php' and 'common/retrieve.php' endpoints.
Recommendations Update LuxSoft LuxCal to a version later than 5.3.4L. Restrict access to the 'rssfeed.php' and 'common/retrieve.php' endpoints to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-36989

Affected Products

Luxcal Web Calendar