CVE-2026-73827: XSS
Published Aug 28, 2026
·Updated
SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to the product.
Affected Software
1 affected component
SOY Calendar
Event History
Aug 28, 2026
CVE Published
via MITRE·06:10 AM
Data Sourced
via MITRE·06:10 AM
DescriptionSeverity
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs low-level privileges and must be able to cause a user to interact with crafted content. Exploitation occurs in the browser of a user logging in to the product.
2
What could successful exploitation allow?
An attacker could execute arbitrary script in the affected user's web browser. The provided impact information indicates potential low confidentiality and integrity impact, with no availability impact.