Junglewise Threat Intelligence

CVE-2026-73827: SOY Calendar cross-site scripting in login

CVE-2026-73827 · Severity: medium · CVSS 5.4 · Published 2026-08-28

Executive brief

SOY Calendar is a web-based calendar application. A cross-site scripting (XSS) vulnerability allows an attacker to inject malicious scripts that execute in the browser of users logging into the product, potentially stealing session credentials or performing unauthorized actions on behalf of the user.

Technical details

This is a cross-site scripting (CWE-79) vulnerability in SOY Calendar that requires an authenticated user to interact with attacker-controlled input during login. The vulnerability allows injection of arbitrary JavaScript that executes in the victim's browser with the privileges of the logged-in user. According to the advisory, the impact is limited to the client-side (cookie/session access and UI manipulation) without server-side compromise. A security patch has been released: SOY Calendar version 2.5.0 addresses this vulnerability and should be deployed immediately.

Affected products

  • Tsuyoshi Saito SOY Calendar 2.4.0 and earlier

Timeline

  • 2026-08-28: disclosed: Vulnerability published in JVN advisory JVN#04485476
  • 2026-08-31: patched: Security update released with SOY Calendar version 2.5.0

References

Related threats