found in Eventobot. This vulnerability allows an attacker to execute
JavaScript code in the victim's browser by sending him/her a malicious
URL using the 'name' parameter in '/search-results'. This vulnerability
can be exploited to steal sensitive user data, such as session cookies,
or to perform actions on behalf of the user.
No analysis available yet.
Vendor Solution
The vulnerability has been fixed by the Eventobot team in the latest version.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 10 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sbitsoft
Sbitsoft eventobot |
|
| CPEs | cpe:2.3:a:sbitsoft:eventobot:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Sbitsoft
Sbitsoft eventobot |
|
| Metrics |
cvssV3_1
|
Mon, 09 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reflected Cross-Site Scripting (XSS) vulnerability has been found in Eventobot. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL using the 'name' parameter in '/search-results'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. | |
| Title | Reflected Cross-Site Scripting (XSS) in Eventobot | |
| First Time appeared |
Eventobot
Eventobot eventobot |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:eventobot:eventobot:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Eventobot
Eventobot eventobot |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-09T20:05:31.167Z
Reserved: 2025-04-16T08:38:10.819Z
Link: CVE-2025-40638
Updated: 2026-03-09T20:05:28.309Z
Status : Analyzed
Published: 2026-03-09T10:16:00.623
Modified: 2026-03-10T19:57:14.373
Link: CVE-2025-40638
No data.
OpenCVE Enrichment
Updated: 2026-03-10T14:07:38Z