CVE-2026-13225 PUBLISHED

Stored XSS in ticket confirmation page

Assigner: rami.io
Reserved: 24.06.2026 Published: 25.06.2026 Updated: 25.06.2026

Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization on the confirmation page for individual tickets in that order.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
CVSS Score: 5.3

Product Status

Vendor pretix
Product pretix
Versions Default: unaffected
  • affected from 0 to 2026.3.4 (excl.)
  • affected from 2026.4.0 to 2026.4.4 (excl.)
  • affected from 2026.5.0 to 2026.5.2 (excl.)

References

Problem Types

  • CWE-80 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) CWE

Impacts

  • CAPEC-592 Stored XSS