← Back

Sbitsoft

sbitsoft

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Eventobot
eventobot

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sbitsoft
1Eventobot
Mar 10, 2026
Mar 9, 2026
8.7 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount....Show more
A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'.Show less
1Sbitsoft
1Eventobot
Mar 10, 2026
Mar 9, 2026
5.1 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
A reflected Cross-Site Scripting (XSS) vulnerability has been found in Eventobot. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL using the '...Show more
A reflected Cross-Site Scripting (XSS) vulnerability has been found in Eventobot. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL using the 'name' parameter in '/search-results'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.Show less