CVE 5.1 MEDIUM

XLSX formula injection in exports_CVE-2026-12862

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

Description

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.

Basic Information

ID CVE-2026-12862
Source rami.io
Published Jun 22, 2026 at 08:26

Affected Product

Vendor pretix
Product Venueless
Version 0.0.0
Affected Versions pretix Venueless 0.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.