CVE 5.3 MEDIUM

Stored XSS in ticket confirmation page_CVE-2026-13225

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

Description

Malicious HTML content could be injected into the email address of an
order, which pretix showed without sanitization on the confirmation page
for individual tickets in that order.

Basic Information

ID CVE-2026-13225
Source rami.io
Published Jun 25, 2026 at 14:26
Modified Jun 25, 2026 at 15:11

Affected Product

Vendor pretix
Product pretix
Affected Versions pretix pretix 0
pretix pretix 2026.4.0
pretix pretix 2026.5.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.