5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
Description
Malicious HTML content could be injected into the email address of an
order, which pretix showed without sanitization on the confirmation page
for individual tickets in that order.
order, which pretix showed without sanitization on the confirmation page
for individual tickets in that order.
Basic Information
ID
CVE-2026-13225
Source
rami.io
Published
Jun 25, 2026 at 14:26
Modified
Jun 25, 2026 at 15:11
Affected Product
Vendor
pretix
Product
pretix
Affected Versions
pretix pretix 0
pretix pretix 2026.4.0
pretix pretix 2026.5.0
pretix pretix 2026.4.0
pretix pretix 2026.5.0