CVE-2026-7175
Multiple vulnerabilities in Entradium by Crocantickets
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;
| CWE | CWE-79 |
| Vendor | crocantickets |
| Product | entradium |
| Published | Oct 1, 2026 |
| Last Updated | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for crocantickets entradium
Be the first to know when new unknown vulnerabilities affecting crocantickets entradium are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Crocantickets / Entradium
versions before 20260409151659 and 20260409153543.
References
Credits
Cosme Vázquez Tomé