CVE-2025-25221
- EPSS 0.04%
- Veröffentlicht 18.02.2025 01:15:09
- Zuletzt bearbeitet 15.09.2025 17:48:07
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.
CVE-2025-25222
- EPSS 0.04%
- Veröffentlicht 18.02.2025 01:15:09
- Zuletzt bearbeitet 15.09.2025 17:44:57
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrieve.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.
CVE-2025-25223
- EPSS 0.05%
- Veröffentlicht 18.02.2025 01:15:09
- Zuletzt bearbeitet 15.09.2025 17:13:19
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.
CVE-2025-25224
- EPSS 0.05%
- Veröffentlicht 18.02.2025 01:15:09
- Zuletzt bearbeitet 15.09.2025 17:07:37
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.
CVE-2023-46700
- EPSS 0.41%
- Veröffentlicht 20.11.2023 05:15:08
- Zuletzt bearbeitet 21.11.2024 08:29:06
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and...
CVE-2023-47175
- EPSS 0.11%
- Veröffentlicht 20.11.2023 05:15:08
- Zuletzt bearbeitet 21.11.2024 08:29:54
Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user ...
CVE-2023-39939
- EPSS 0.18%
- Veröffentlicht 21.08.2023 09:15:10
- Zuletzt bearbeitet 21.11.2024 08:16:04
SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter...
CVE-2023-39543
- EPSS 0.27%
- Veröffentlicht 21.08.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 08:15:38
Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user ...