Pretix / Venueless
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-82838 | Default webserver configuration with incorrect CSP | MEDIUM | 6.4 | Aug 31, 2026 |
| CVE-2026-13350 | Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create. | LOW | 2.3 | Jun 25, 2026 |
| CVE-2026-12863 | Open redirect | MEDIUM | 5.1 | Jun 22, 2026 |
| CVE-2026-12862 | XLSX formula injection in exports | MEDIUM | 5.1 | Jun 22, 2026 |
| CVE-2026-5599 | API allows deletion of users of other instance | HIGH | 7.3 | Apr 5, 2026 |
| CVE-2026-4982 | Unauthorized access to chat contents | HIGH | 7.3 | Mar 27, 2026 |
Showing 1 to 5 of 5 CVEs