Luxsoft maintains a narrow product line centered on LuxCal, a web-based calendar application, where disclosed vulnerabilities skew strongly toward critical severity. The vendor's exposure recurs through application-layer input-handling and authentication weaknesses, including SQL injection, cross-site scripting, path traversal, and missing authentication for critical functions, which are characteristic risks in web calendar platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Luxsoft over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45915CRITICAL In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the attacker's session to be authenticated as any registered Lux | May 24, 2022 | 9.8 | 29 | NO | NO |
CVE-2023-46700CRITICAL SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker | Nov 20, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-25222CRITICAL The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrieve.php. If this vulnerability is explo | Feb 18, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-25221CRITICAL The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If this vulnerability is exploited, | Feb 18, 2025 | 9.8 | 27 | NO | NO |
CVE-2023-39939CRITICAL SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker | Aug 21, 2023 | 9.1 | 25 | NO | NO |
CVE-2021-45914CRITICAL In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered Lux | May 24, 2022 | 9.8 | 24 | NO | NO |
CVE-2025-25224HIGH The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dloader.php. If this vulnerability i | Feb 18, 2025 | 7.5 | 19 | NO | NO |
CVE-2023-39543MEDIUM Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated a | Aug 21, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-47175MEDIUM Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated a | Nov 20, 2023 | 6.1 | 18 | NO | NO |
CVE-2025-25223MEDIUM The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloader.php. If this vulnerability is exploi | Feb 18, 2025 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Luxsoft.
Media articles that mention a CVE ID that affects a product developed by Luxsoft — matched by CVE ID, not by vendor name.