PT-2026-52442 · Git+1 · Pretix

CVE-2026-13225

·

Published

2026-06-25

·

Updated

2026-06-25

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions pretix (affected versions not specified)
Description Malicious HTML content can be injected into the email address of an order. The system displays this content without sanitization on the confirmation page for individual tickets within that order, leading to a cross-site scripting risk.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13225

Affected Products

Pretix