VYPR

Entradium

by Crocantickets

CVEs (2)

  • CVE-2026-7174MedOct 1, 2026
    risk 0.31cvss —epss —

    CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during the process of creating discounts assigned to an event. This vulnerability allows…

  • CVE-2026-7173MedOct 1, 2026
    risk 0.31cvss —epss —

    CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data. * (Stored XSS) The City parameter in the endpoint…