Junglewise Threat Intelligence

CVE-2026-77838: SOY Calendar cross-site scripting in login

CVE-2026-77838 · Severity: medium · CVSS 5.4 · Published 2026-08-28

Executive brief

SOY Calendar is a web-based calendar application. The product contains a cross-site scripting (XSS) vulnerability in the login functionality that allows attackers to inject and execute arbitrary JavaScript in the browsers of users attempting to log in, potentially compromising user sessions or stealing credentials.

Technical details

SOY Calendar versions 2.4.0 and earlier contain a stored or reflected cross-site scripting (XSS) vulnerability (CWE-79) in the login component. The vulnerability requires authentication (login) and user interaction (e.g., clicking a malicious link), allowing an attacker to inject arbitrary JavaScript that executes in the victim's browser within the SOY Calendar context. Successful exploitation can lead to session hijacking, credential theft, or malware injection. The vulnerability has been patched in version 2.5.0 and later, released on August 31, 2026.

Affected products

  • Tsuyoshi Saito SOY Calendar 2.4.0 and earlier

Timeline

  • 2026-08-28: disclosed
  • 2026-08-31: patched: SOY Calendar version 2.5.0 released with security fixes

References

Related threats