Pretix · Venueless · CVE-2026-12862
**Name of the Vulnerable Software and Affected Versions**
The product name cannot be determined (affected versions not specified)
**Description**
Untrusted user data is passed verbatim to Excel exports for administrators. This allows formula injection, a technique where an attacker inserts malicious formulas into a spreadsheet, which can be used to compromise the environment of the user loading the file or access other data within the file.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.