CVE-2026-101268Low· 1.7▾ SunlitIf an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacke…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 9.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101267Low· 2.7A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information
CVE-2026-101269Low· 2.3The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users
CVE-2026-101270Low· 2.1Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
CVE-2026-101271Low· 2.1OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
CVE-2026-101266Low· 1.3A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps.
CVE-2025-14881Lowpretix has Broken Access Control Allowing Cross-User File Access via UUID