pretix records
7 published records for vendor pretix.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-627 Dynamic Variable Evaluation3
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-20 Improper Input Validation1
- CWE-653 Improper Isolation or Compartmentalization1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-27447No exploit | pretix before 2024.1.1 mishandles file validation.pretix · pretix · CWE-20 | Critical9.8 | — | 0.8% | Feb 26, 2024 |
30Monitor | CVE-2026-2452No exploit | Unsafe variable evaluation in email templatespretix · newsletters · CWE-627 | High7.5 | — | 0.3% | Feb 16, 2026 |
30Monitor | CVE-2026-2451No exploit | Unsafe variable evaluation in email templatespretix · double opt in step · CWE-627 | High7.5 | — | 0.3% | Feb 16, 2026 |
30Monitor | CVE-2026-2415No exploit | Unsafe variable evaluation in email templatespretix · pretix · CWE-627 | High7.5 | — | 0.3% | Feb 16, 2026 |
28Monitor | CVE-2024-8113No exploit | Stored XSS in Placeholder Samples in Mail Previewpretix · pretix · CWE-79 | High7.2 | — | 0.3% | Aug 23, 2024 |
22Monitor | CVE-2026-5600No exploit | A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-pretix · pretix · CWE-653 | Medium5.5 | — | 0.3% | Apr 8, 2026 |
9Monitor | CVE-2025-13742No exploit | Limited HTML injection in emailspretix · pretix · CWE-116 | Low2.4 | — | 0.2% | Nov 27, 2025 |
- CVE-2024-2744739Monitor
pretix before 2024.1.1 mishandles file validation.
CriticalCVSS 9.8No exploitEPSS 1%pretix · pretixFeb 26, 2024
- CVE-2026-245230Monitor
Unsafe variable evaluation in email templates
HighCVSS 7.5No exploitEPSS 0%pretix · newslettersFeb 16, 2026
- CVE-2026-245130Monitor
Unsafe variable evaluation in email templates
HighCVSS 7.5No exploitEPSS 0%pretix · double opt in stepFeb 16, 2026
- CVE-2026-241530Monitor
Unsafe variable evaluation in email templates
HighCVSS 7.5No exploitEPSS 0%pretix · pretixFeb 16, 2026
- CVE-2024-811328Monitor
Stored XSS in Placeholder Samples in Mail Preview
HighCVSS 7.2No exploitEPSS 0%pretix · pretixAug 23, 2024
- CVE-2026-560022Monitor
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-
MediumCVSS 5.5No exploitEPSS 0%pretix · pretixApr 8, 2026
- CVE-2025-137429Monitor
Limited HTML injection in emails
LowCVSS 2.4No exploitEPSS 0%pretix · pretixNov 27, 2025