CVE-2025-14882Low▾ Sunlitpretix has Broken Access Control Allowing Cross-User File Access via UUID
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.2%
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
pretix >= 2025.10.0, < 2025.10.1pretix >= 2025.9.0, < 2025.9.3pretix < 2025.8.3Upgrade to a patched release:
pretix 2025.10.1pretix 2025.9.3pretix 2025.8.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14881Lowpretix has Broken Access Control Allowing Cross-User File Access via UUID
CVE-2023-44464High· 7.8pretix allows Pillow to parse EPS files
CVE-2026-9712Lowpretix vulnerable to Authorization Bypass Through User-Controlled Key