CVE-2026-13225
MEDIUM
5.3
CVSS 4.0
Description
Malicious HTML content could be injected into the email address of an
order, which pretix showed without sanitization on the confirmation page
for individual tickets in that order.
Metadata
Severity & Metrics
5.3
MEDIUM CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| pretix | pretix | — | 0 < 2026.3.4, 2026.4.0 < 2026.4.4, 2026.5.0 < 2026.5.2 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-80 | cna | CWE-80 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.3 | MEDIUM | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L |
References (1)