CVE-2026-13225
EUVD-2026-3941825.06.2026, 15:16
Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization on the confirmation page for individual tickets in that order.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| pretix | pretix | 𝑥 < 2026.3.4 | CNA |
| pretix | pretix | 2026.4.0 ≤ 𝑥 < 2026.4.4 | CNA |
| pretix | pretix | 2026.5.0 ≤ 𝑥 < 2026.5.2 | CNA |