Pretix is a focused open-source event ticketing and registration platform whose vulnerability footprint concentrates in its core ticketing product and related modules such as double opt-in and newsletter handling. The recurring exposure centers on web-application input and output handling, including dynamic code evaluation, output encoding failures, input validation gaps, and cross-site scripting conditions that are characteristic of template-driven and user-input-dependent features; vulnerabilities affecting the vendor skew toward serious outcomes. Defenders deploying Pretix should prioritize security updates for the ticketing and customer-communication tier; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pretix over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57532HIGH Malicious HTML content contained in the layout specification of a PDF
ticket or badge layout was executed when the PDF editor is opened in the
browser. This could allow one backe | Jun 25, 2026 | 8.8 | 35 | NO | NO |
CVE-2024-27447CRITICAL pretix before 2024.1.1 mishandles file validation. | Feb 26, 2024 | 9.8 | 26 | NO | NO |
CVE-2026-13225MEDIUM Malicious HTML content could be injected into the email address of an
order, which pretix showed without sanitization on the confirmation page
for individual tickets in that orde | Jun 25, 2026 | 5.3 | 25 | NO | NO |
CVE-2026-2452MEDIUM Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name}
is used in an email template, it will be replaced with the buyer's | Feb 16, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-2451MEDIUM Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name}
is used in an email template, it will be replaced with the buyer's | Feb 16, 2026 | 6.5 | 22 | NO | NO |
When creating an export of all reusable media, the secrets of connected
gift cards were included in the export even if the user creating the
export does not have permission to vi | Jun 9, 2026 | 3.6 | 21 | NO | NO |
CVE-2025-13742MEDIUM Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's n | Nov 27, 2025 | 6.1 | 21 | NO | NO |
When creating an export through the pretix API, API clients are
returned an UUID value for their export job (a long, random string like
35742818-c375-4d15-839f-d49aecce94d6). Usi | May 27, 2026 | 3.8 | 20 | NO | NO |
CVE-2026-5600MEDIUM A new API endpoint introduced in pretix 2025 that is supposed to
return all check-in events of a specific event in fact returns all
check-in events belonging to the respective or | Apr 8, 2026 | 4.3 | 19 | NO | NO |
CVE-2026-2415MEDIUM Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name}
is used in an email template, it will be replaced with the buyer's | Feb 16, 2026 | 5.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pretix.
Media articles that mention a CVE ID that affects a product developed by Pretix — matched by CVE ID, not by vendor name.