CVE-2026-57533

EUVD-2026-39423
Malicious HTML content could be injected into the page pretix shows when
 redirection to an untrusted page occurs. Since this page has a 
Content-Security-Policy, this can mainly be used for phishing purposes.
Basic XSS
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
rami.ioCNA
2.1 LOW
NETWORK
HIGH
LOW
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
pretixpretix
𝑥
< 2026.3.4
CNA
pretixpretix
2026.4.0 ≤
𝑥
< 2026.4.4
CNA
pretixpretix
2026.5.0 ≤
𝑥
< 2026.5.2
CNA