CVE-2025-40639: Sbitsoft Eventobot
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'.
Affected products
- Sbitsoft Eventobot: affected versions not specified
Published 2026-03-09. Last modified 2026-10-07.