CVE-2026-101271
- EPSS 0.17%
- Veröffentlicht 29.09.2026 13:17:49
- Zuletzt bearbeitet 29.09.2026 21:28:02
OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
CVE-2026-101270
- EPSS 0.19%
- Veröffentlicht 29.09.2026 13:17:49
- Zuletzt bearbeitet 29.09.2026 21:28:02
Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
CVE-2026-101269
- EPSS 0.22%
- Veröffentlicht 29.09.2026 13:17:49
- Zuletzt bearbeitet 29.09.2026 21:28:02
The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only e...
CVE-2026-101268
- EPSS 0.2%
- Veröffentlicht 29.09.2026 13:17:49
- Zuletzt bearbeitet 29.09.2026 21:28:02
If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. ...
CVE-2026-101267
- EPSS 0.24%
- Veröffentlicht 29.09.2026 13:17:49
- Zuletzt bearbeitet 29.09.2026 21:28:02
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
CVE-2026-101266
- EPSS 0.27%
- Veröffentlicht 29.09.2026 12:17:09
- Zuletzt bearbeitet 29.09.2026 21:28:02
A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps.
CVE-2026-18028
- EPSS 0.21%
- Veröffentlicht 28.07.2026 10:39:48
- Zuletzt bearbeitet 30.07.2026 16:43:03
The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of an event in just a few clicks. This view did not properly check that the user has permission to change configuration for the giv...
CVE-2026-13602
- EPSS 0.27%
- Veröffentlicht 01.07.2026 13:45:30
- Zuletzt bearbeitet 02.07.2026 18:43:45
We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: * The payment integration plugins Stripe (included in the core system), pretix-mollie, p...
CVE-2026-57532
- EPSS 0.33%
- Veröffentlicht 25.06.2026 14:32:37
- Zuletzt bearbeitet 25.06.2026 16:16:43
Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one backend user to inject JavaScript into the browser context of another back...
CVE-2026-57533
- EPSS 0.25%
- Veröffentlicht 25.06.2026 14:31:18
- Zuletzt bearbeitet 25.06.2026 16:16:43
Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since this page has a Content-Security-Policy, this can mainly be used for phishing purposes.