VYPR

Pretix

by Pretix

pypi: pretix

Source repositories

CVEs (26)

  • CVE-2026-57536MedJun 25, 2026
    risk 0.00cvss epss 0.00

    Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one…

  • CVE-2026-57535LowJun 25, 2026
    risk 0.00cvss epss 0.00

    Content injected to PDF rendering contexts could, in many places, include HTML content including tags. If the src attribute of these images pointed to an URL, the PDF rendering engine would download the image from that place and display it, thereby leaking information…

  • CVE-2026-57534LowJun 25, 2026
    risk 0.00cvss epss 0.00

    Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.

  • CVE-2026-57533LowJun 25, 2026
    risk 0.00cvss epss 0.00

    Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since this page has a Content-Security-Policy, this can mainly be used for phishing purposes.

  • CVE-2026-57532HigJun 25, 2026
    risk 0.00cvss epss 0.00

    Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one backend user to inject JavaScript into the browser context of another backend user. Due to requirements…

  • CVE-2026-13314LowJun 25, 2026
    risk 0.00cvss epss 0.00

    Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.

Page 2 of 2