CVE-2026-101270Low· 2.1▾ SunlitMalicious HTML content could be injected into the help texts of various fields with organizer permissions.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 11.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
pretix >= 0.0 < 2026.5.5pretix >= 2026.6.0 < 2026.6.2pretix >= 2026.7.0 < 2026.7.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101267Low· 2.7Revenue information leak
CVE-2026-101268Low· 1.7Customer session fixation
CVE-2026-101269Low· 2.3Incorrect session validation for API-uploaded files
CVE-2026-101271Low· 2.1OAuth credentials not disabled when application is disabled
CVE-2026-101266Low· 1.3A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps.
CVE-2025-14881Lowpretix has Broken Access Control Allowing Cross-User File Access via UUID