Sbitsoft operates a narrowly scoped product portfolio, with disclosure activity concentrated in its EventBot application, an event management and automation tool. The vendor's observed vulnerability profile centers on application-layer input handling, with recurrent weaknesses in cross-site scripting and SQL injection that are typical of web-facing business software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sbitsoft over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-40639CRITICAL A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter | Mar 9, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-40638MEDIUM A reflected Cross-Site Scripting (XSS) vulnerability has been
found in Eventobot. This vulnerability allows an attacker to execute
JavaScript code in the victim's browser by send | Mar 9, 2026 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sbitsoft.
Media articles that mention a CVE ID that affects a product developed by Sbitsoft — matched by CVE ID, not by vendor name.