CVE-2025-31838

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 1, 2025
CWE ID 79

Summary

CVE-2025-31838 is a Cross-site Scripting (XSS) vulnerability affecting the Eventbee RSVP Widget. The issue stems from improper neutralization of user input during web page generation. Malicious scripts can be injected into the widget, allowing attackers to execute arbitrary code in the context of affected users' browsers. This can lead to unauthorized access, data theft, or manipulation of user sessions. The affected version range is from n/a to 1.0. Users are advised to update the widget as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share