Pretix
by Pretix
Source repositories
CVEs (26)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-57536 | Med | 0.00 | — | 0.00 | Jun 25, 2026 | Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one… | ||
| CVE-2026-57535 | Low | 0.00 | — | 0.00 | Jun 25, 2026 | Content injected to PDF rendering contexts could, in many places, include HTML content including tags. If the src attribute of these images pointed to an URL, the PDF rendering engine would download the image from that place and display it, thereby leaking information… | ||
| CVE-2026-57534 | Low | 0.00 | — | 0.00 | Jun 25, 2026 | Malicious HTML content could be injected into the content of a page in the pretix-pages plugin. | ||
| CVE-2026-57533 | Low | 0.00 | — | 0.00 | Jun 25, 2026 | Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since this page has a Content-Security-Policy, this can mainly be used for phishing purposes. | ||
| CVE-2026-57532 | Hig | 0.00 | — | 0.00 | Jun 25, 2026 | Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one backend user to inject JavaScript into the browser context of another backend user. Due to requirements… | ||
| CVE-2026-13314 | Low | 0.00 | — | 0.00 | Jun 25, 2026 | Malicious HTML content could be injected into the content rendered by the pretix-digital plugin. |
- risk 0.00cvss —epss 0.00
Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one…
- risk 0.00cvss —epss 0.00
Content injected to PDF rendering contexts could, in many places, include HTML content including tags. If the src attribute of these images pointed to an URL, the PDF rendering engine would download the image from that place and display it, thereby leaking information…
- risk 0.00cvss —epss 0.00
Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.
- risk 0.00cvss —epss 0.00
Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since this page has a Content-Security-Policy, this can mainly be used for phishing purposes.
- risk 0.00cvss —epss 0.00
Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one backend user to inject JavaScript into the browser context of another backend user. Due to requirements…
- risk 0.00cvss —epss 0.00
Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.
Page 2 of 2