rami.io GmbH

First CVE: Aug 23, 2024Active for: 2 years
27
CVEs Published
More CVEs Published than 46% of tracked CNAs
9.0
Avg CVEs / Year
More Avg CVEs / Year than 50% of tracked CNAs
5.3
Avg CVSS Score
Higher Avg CVSS Score than 4% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by rami.io GmbH over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 23, 2024
22 months ago
Most Recent CVE
Jul 1, 2026
22 days ago

Top CVEs

All CVEs published by rami.io GmbH as a CNA, regardless of affected vendor or product.

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially others based on Oppwa's technology. The integration of Oppwa, f
Jul 1, 20269.037NONO
We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: * The payment inte
Jul 1, 20267.735NONO
Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one backe
Jun 25, 20268.835NONO
An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.
Jun 22, 20265.128NONO
Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the
Jun 22, 20265.128NONO
A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds.
Apr 5, 20267.328NONO
Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it
Jun 25, 20266.327NONO
Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from on
Jun 25, 20266.327NONO
Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one p
Jun 25, 20266.327NONO
Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization on the confirmation page for individual tickets in that orde
Jun 25, 20265.325NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA27 CVEs
Severity distribution among all CVEs352,101 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (77.8%)
High6 (22.2%)
Unknown0 (0.0%)
User Interaction
None17 (63.0%)
Unknown0 (0.0%)
Required2 (7.4%)
Privileges Required
Low15 (55.6%)
High5 (18.5%)
None7 (25.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by rami.io GmbH as a CNA.

Media Mentions

Media articles that mention a CVE ID published by rami.io GmbH as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs