216.73.216.197

CVE-2025-40638

· Published 09/03/2026 10:16 · Modified 10/03/2026 19:57

Labels: CVE-2025-40638 2026-03-09CVE-2025-40638CWE-79[email protected]

Essential information

Published
09/03/2026 10:16
Modified
10/03/2026 19:57
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A reflected Cross-Site Scripting (XSS) vulnerability has been found in Eventobot. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL using the 'name' parameter in '/search-results'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sbitsoft / eventobot cpe:2.3:a:sbitsoft:eventobot:-:*:*:*:*:*:*:*

References