CVE-2026-57532
- EPSS -
- Veröffentlicht 25.06.2026 14:32:37
- Zuletzt bearbeitet 25.06.2026 16:16:43
Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one backend user to inject JavaScript into the browser context of another back...
CVE-2026-57533
- EPSS -
- Veröffentlicht 25.06.2026 14:31:18
- Zuletzt bearbeitet 25.06.2026 16:16:43
Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since this page has a Content-Security-Policy, this can mainly be used for phishing purposes.
CVE-2026-57535
- EPSS -
- Veröffentlicht 25.06.2026 14:29:18
- Zuletzt bearbeitet 25.06.2026 16:16:43
Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src attribute of these images pointed to an URL, the PDF rendering engine would download the image from that place and display it, t...
CVE-2026-13225
- EPSS -
- Veröffentlicht 25.06.2026 14:26:31
- Zuletzt bearbeitet 25.06.2026 16:16:33
Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization on the confirmation page for individual tickets in that order.
CVE-2026-11764
- EPSS 0.23%
- Veröffentlicht 09.06.2026 11:54:37
- Zuletzt bearbeitet 09.06.2026 13:57:49
When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if the user creating the export does not have permission to view gift cards. This is inconsistent with the UI and API where only th...
CVE-2026-9712
- EPSS 0.22%
- Veröffentlicht 27.05.2026 15:16:36
- Zuletzt bearbeitet 27.05.2026 19:59:03
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for dow...
CVE-2026-5600
- EPSS 0.26%
- Veröffentlicht 08.04.2026 12:24:51
- Zuletzt bearbeitet 24.04.2026 17:46:14
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all ot...
CVE-2026-2452
- EPSS 0.26%
- Veröffentlicht 16.02.2026 10:16:22
- Zuletzt bearbeitet 12.03.2026 17:29:01
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. This mechanism contained a security-releva...
CVE-2026-2451
- EPSS 0.26%
- Veröffentlicht 16.02.2026 10:16:05
- Zuletzt bearbeitet 13.03.2026 12:39:56
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. This mechanism contained a security-releva...
CVE-2026-2415
- EPSS 0.24%
- Veröffentlicht 16.02.2026 10:15:09
- Zuletzt bearbeitet 13.03.2026 12:47:32
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. This mechanism contained two security-rele...