pretix

6 known vulnerabilities in pretix, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-101271 CVSS 2.1 low OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to…
  • CVE-2026-101270 CVSS 2.1 low Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
  • CVE-2026-101269 CVSS 2.3 low The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is…
  • CVE-2026-101268 CVSS 1.7 low If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If…
  • CVE-2026-101267 CVSS 2.7 low A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some…
  • CVE-2026-101266 CVSS 1.3 low A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps.