eventobot vulnerabilities
CVEs whose affected-version data names the eventobot package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-40639Critical· 9.8A SQL injection vulnerability has been found in Eventobot
A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'.
▾ Midnightsbitsoft · eventobotEPSS 0.33%via NVD
CVE-2025-40638Medium· 6.1A reflected Cross-Site Scripting (XSS) vulnerability has been found in Eventobot
A reflected Cross-Site Scripting (XSS) vulnerability has been found in Eventobot. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL using the 'name' parameter i…
▾ Sunlitsbitsoft · eventobotEPSS 0.21%via NVD