VulnSea

Entradium vulnerabilities

CVEs whose affected-version data names the Entradium package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-7176Medium· 4.8
today

CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an event, which allows for the inject…

CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an event, which allows for the inject…

▾ SunlitCrocantickets · Entradiumvia NVD
CVE-2026-7175Medium· 4.8
today

CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;

CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;

▾ SunlitCrocantickets · Entradiumvia NVD
CVE-2026-7174Medium· 4.8
today

CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets

CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during the process of creating discounts assig…

▾ SunlitCrocantickets · Entradiumvia NVD
CVE-2026-7173Medium· 4.8
today

CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets

CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data. * (Stored …

▾ SunlitCrocantickets · Entradiumvia NVD
Entradium vulnerabilities (CVEs) · VulnSea