generated: '2026-09-07' method: searched probe: true source: >- https://www.cvent.com/en/event-management-software/vulnerability-disclosure-program (HTTP 200, fetched 2026-09-07); https://www.cvent.com/en/event-management-software/report-security-vulnerability (HTTP 200); https://trust.cvent.com/ (HTTP 200) program: published: true name: Cvent Vulnerability Disclosure Program url: https://www.cvent.com/en/event-management-software/vulnerability-disclosure-program report_form: https://www.cvent.com/en/event-management-software/report-security-vulnerability contact_email: security@cvent.com bug_bounty: false rewards: false platform: null scope_note: >- The program is published by Cvent for the Cvent estate, which includes the community.cvent.com and support.cvent.com hosts this record covers. It is not a Cvent-Community-specific policy. policy: - https://www.cvent.com/en/event-management-software/vulnerability-disclosure-program contact: - security@cvent.com security_txt: served: false probed: - https://community.cvent.com/.well-known/security.txt - https://support.cvent.com/.well-known/security.txt - https://release.cvent.com/.well-known/security.txt - https://status.cvent.com/.well-known/security.txt - https://www.cvent.com/.well-known/security.txt - https://cvent.com/.well-known/security.txt note: >- No RFC 9116 file on any host. community.cvent.com answers 200 with its HTML catch-all shell, support.cvent.com answers 401, and the rest 404. An automated scanner finds nothing at the machine-readable path even though a disclosure program exists. evidence: - source: https://www.cvent.com/en/event-management-software/vulnerability-disclosure-program kind: disclosure-policy http_status: 200 - source: https://www.cvent.com/en/event-management-software/report-security-vulnerability kind: report-form http_status: 200 - source: https://trust.cvent.com/ kind: trust-center http_status: 200