Crocantickets has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was October 2026 with 4. The median CVSS is 4.8 (medium). The most common weakness class is CWE-79 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.8
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Weakness classes
Products
- Entradium 4
Worst active — by depth score
CVE-2026-7176Medium· 4.8CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an event, which allows for the inject…26CVE-2026-7175Medium· 4.8CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;26CVE-2026-7174Medium· 4.8CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets26CVE-2026-7173Medium· 4.8CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets26
Crocantickets vulnerabilities
CVEs affecting Crocantickets, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-7176Medium· 4.8CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an event, which allows for the inject…
CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an event, which allows for the inject…
CVE-2026-7175Medium· 4.8CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;
CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;
CVE-2026-7174Medium· 4.8CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets
CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during the process of creating discounts assig…
CVE-2026-7173Medium· 4.8CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets
CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data. * (Stored …