Topic: LuxCal 5.3.5 - SQL injection vulnerability
27 August 2026 JPCERT/CC Cyber Security reported an SQL injection vulnerability (ID JVN#65245156) for the LuxCal web calendar.
It was confirmed that authentication could be bypassed to access administrator pages.
You can fix this problem by downloading the following zip-file and by reading the instruction in this file: fix-20260905