CVE-2026-7173
Received
Received - Intake
Stored XSS in Crocantickets Entradium Event Management
Vulnerability report for CVE-2026-7173, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-01
Last updated on: 2026-10-01
Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)
Description
Description
CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data.
* (Stored XSS) The City parameter in the endpoint /events/<event_name>/edit_general during the process of creating or editing events assigned to a promoter allows for the injection of JavaScript that will execute on the eventβs public page.
* (Reflected XSS) The Description parameter in the endpoint /events/<event_name>/edit-general when attempting to create or modify an event without filling in all required fields.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| crocantickets | entradium | * |
| crocantickets | entradium | 20260409151659 |
| crocantickets | entradium | 20260409153543 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |