CVE-2026-13225

Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization on the confirmation page for individual tickets in that order.
CVSS

No CVSS.

Configurations

No configuration.

History

25 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-25 15:16

Updated : 2026-06-25 16:16


NVD link : CVE-2026-13225

Mitre link : CVE-2026-13225

CVE.ORG link : CVE-2026-13225


JSON object : View

Products Affected

No product.

CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)