Pretalx is a narrowly scoped event-management and conference-organization platform whose vulnerability profile centers on its core product and reflects input-handling challenges common to web applications. The recurring weakness classes—path traversal, cross-site scripting, and output-encoding issues—indicate a focus on input validation and output sanitization in a user-facing web tier. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pretalx over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28459MEDIUM pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigger the reading of arbitrary file | Apr 20, 2023 | 6.5 | 34 | NO | YES |
CVE-2023-28458MEDIUM pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the overwriting (with the standard pretalx 404 page content) of an a | Apr 20, 2023 | 4.3 | 26 | NO | YES |
CVE-2026-41426MEDIUM pretalx is a conference planning tool. Prior to 2026.1.0, an unauthenticated attacker can send arbitrary HTML-rendered emails from a pretalx instance's configured sender address by | Apr 24, 2026 | 6.1 | 25 | NO | NO |
CVE-2026-41241MEDIUM pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submission titles, speaker display names, and user names/emails into | Apr 23, 2026 | 5.4 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pretalx.
Media articles that mention a CVE ID that affects a product developed by Pretalx — matched by CVE ID, not by vendor name.