rami.io GmbH
First CVE: Aug 23, 2024Active for: 2 years
27
CVEs Published
More CVEs Published than 46% of tracked CNAs
9.0
Avg CVEs / Year
More Avg CVEs / Year than 50% of tracked CNAs
5.3
Avg CVSS Score
Higher Avg CVSS Score than 4% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by rami.io GmbH over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 23, 2024
22 months ago
Most Recent CVE
Jul 1, 2026
22 days ago
Top CVEs
All CVEs published by rami.io GmbH as a CNA, regardless of affected vendor or product.
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13603CRITICAL The payment integration pretix-oppwa provides support
for the payment providers VR Payment, Hobex, and potentially others
based on Oppwa's technology. The integration of Oppwa, f | Jul 1, 2026 | 9.0 | 37 | NO | NO |
CVE-2026-13602HIGH We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data:
*
The payment inte | Jul 1, 2026 | 7.7 | 35 | NO | NO |
CVE-2026-57532HIGH Malicious HTML content contained in the layout specification of a PDF
ticket or badge layout was executed when the PDF editor is opened in the
browser. This could allow one backe | Jun 25, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-12863MEDIUM An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains. | Jun 22, 2026 | 5.1 | 28 | NO | NO |
CVE-2026-12862MEDIUM Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the | Jun 22, 2026 | 5.1 | 28 | NO | NO |
CVE-2026-5599HIGH A user with API access and "manage users" permission in any venueless
world is able to trigger deletion of user accounts in other worlds. | Apr 5, 2026 | 7.3 | 28 | NO | NO |
CVE-2026-57536MEDIUM Our payment integration with Mollie did not properly validate payment
status responses. An attacker could use a successful payment status
response from one payment and supply it | Jun 25, 2026 | 6.3 | 27 | NO | NO |
CVE-2026-13223MEDIUM Our payment integration with Computop-based payment methods did not
properly validate payment status responses. An attacker could use a
successful payment status response from on | Jun 25, 2026 | 6.3 | 27 | NO | NO |
CVE-2026-13222MEDIUM Our payment integration with Oppwa-based payment methods did not
properly validate payment status responses. An attacker could use a
successful payment status response from one p | Jun 25, 2026 | 6.3 | 27 | NO | NO |
CVE-2026-13225MEDIUM Malicious HTML content could be injected into the email address of an
order, which pretix showed without sanitization on the confirmation page
for individual tickets in that orde | Jun 25, 2026 | 5.3 | 25 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA27 CVEs
33%
44%
19%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (77.8%)
High6 (22.2%)
Unknown0 (0.0%)
User Interaction
None17 (63.0%)
Unknown0 (0.0%)
Required2 (7.4%)
Privileges Required
Low15 (55.6%)
High5 (18.5%)
None7 (25.9%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (27 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by rami.io GmbH as a CNA.
Media Mentions
Media articles that mention a CVE ID published by rami.io GmbH as a CNA — matched by CVE ID, not by organization name.