Description
CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an event, which allows for the injection of JavaScript that will execute on the public ticket purchase page for the event.
Published: 2026-10-01
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Client‑side XSS on public ticket purchase page
Action: Patch immediately
AI Analysis

Impact

The vulnerability allows an attacker to inject arbitrary JavaScript into the Help text and Title fields of ticket sale forms during creation or modification. When a user visits the public ticket purchase page for the event, the injected script executes in the user’s browser, potentially enabling session theft, defacement, or other malicious client‑side actions. This client‑side code injection falls under CWE‑79 and can compromise user confidentiality and integrity, but it does not provide direct server‑side code execution.

Affected Systems

The flaw exists in Crocantickets’ Entradium platform in all versions prior to the builds dated 20260409151659 and 20260409153543. Customers using any older Entradium release should treat the application as vulnerable until they apply the vendor’s fix.

Risk and Exploitability

The CVSS score of 4.8 reflects a moderate severity for an XSS that does not require user interaction. No EPSS data are available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is an authenticated discovery and modification of event forms by users who have administrative or event‑organizer privileges. Once the malicious code runs in an end‑user’s browser, the attacker can steal session cookies, deface the page, or redirect the user to phishing sites.

Generated by OpenCVE AI on October 1, 2026 at 11:57 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed by Crocantickets team in versions 20260409151659 y 20260409153543.


OpenCVE Recommended Actions

  • Upgrade the Entradium platform to at least version 20260409151659 or 20260409153543 to apply the vendor fix.
  • Restrict or remove the ability for non‑privileged users to edit the Help text and Title fields of event forms until the patch is installed.
  • Deploy a content security policy that disallows inline JavaScript on the public ticket purchase pages and employ a web application firewall to block malicious script payloads entering form submissions.

Generated by OpenCVE AI on October 1, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 10:00:00 +0000

Type Values Removed Values Added
Description CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an event, which allows for the injection of JavaScript that will execute on the public ticket purchase page for the event.
Title Multiple vulnerabilities in Entradium by Crocantickets
First Time appeared Crocantickets
Crocantickets entradium
Weaknesses CWE-79
CPEs cpe:2.3:a:crocantickets:entradium:versions_before_20260409151659_and_20260409153543.:*:*:*:*:*:*:*
Vendors & Products Crocantickets
Crocantickets entradium
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Crocantickets Entradium
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-01T19:20:00.710Z

Reserved: 2026-04-27T07:58:56.358Z

Link: CVE-2026-7176

cve-icon Vulnrichment

Updated: 2026-10-01T19:19:57.334Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T10:17:17.100

Modified: 2026-10-01T20:17:31.243

Link: CVE-2026-7176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:35:42Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')