pretix
Ticket shop application for conferences, festivals, concerts, tech events, shows, exhibitions, workshops, barcamps, etc.
Activity
- Latest release
- 1mo ago
- Total releases
- 199
- Cadence
- ~2 days
- Last 12 months
- 40
Reach
- Stars
- 2.5k
Details
- License
- custom
- First release
- Jan 04, 2017
| Version | Released | |
|---|---|---|
2026.7.0
minor
| ||
2026.6.1
patch
| ||
2026.4.6
patch
| ||
2026.5.4
patch
| ||
2026.6.0
minor
| ||
2026.4.5
patch
| ||
2026.5.3
patch
| ||
2026.3.5.post1
pre
1 CVE
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2026.4.4
patch
| ||
2026.3.4
patch
1 CVE
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2026.5.2
patch
| ||
2026.4.3
patch
| ||
2026.3.3
patch
1 CVE
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2026.5.1
patch
| ||
2026.5.0
minor
| ||
2026.2.2
patch
1 CVE
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2026.3.2
patch
1 CVE
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2026.4.2
patch
| ||
2026.4.1
patch
1 CVE
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2026.4.0
minor
1 CVE
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2026.1.2
patch
1 CVE
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2026.2.1
patch
1 CVE
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2026.3.1
patch
1 CVE
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2026.3.0
minor
2 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5600
GHSA-wr8q-c73g-m7gp
PYSEC-2026-111
Apr 08, 2026
pretix: API leaks check-in data between events of the same organizer
Medium
Network
Low
High
None
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those they should not have access to. These records contain information on the time and result of every ticket scan as well as the ID of the matched ticket. Example: { "id": 123, "successful": true, "error_reason": null, "error_explanation": null, "position": 321, "datetime": "2020-08-23T09:00:00+02:00", "list": 456, "created": "2020-08-23T09:00:00+02:00", "auto_checked_in": false, "gate": null, "device": 1, "device_id": 1, "type": "entry" } An unauthorized user usually has no way to match these IDs (position) back to individual people. Affected versions
2026.3.0
2026.2.0
2025.10.0
2025.10.1
2025.10.2
2026.1.0
2026.1.1
Fixed in
2026.1.2
2026.2.1
2026.3.1
References Updated Jun 08, 2026 · Source: OSV.dev | ||
2026.2.0
minor
2 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5600
GHSA-wr8q-c73g-m7gp
PYSEC-2026-111
Apr 08, 2026
pretix: API leaks check-in data between events of the same organizer
Medium
Network
Low
High
None
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those they should not have access to. These records contain information on the time and result of every ticket scan as well as the ID of the matched ticket. Example: { "id": 123, "successful": true, "error_reason": null, "error_explanation": null, "position": 321, "datetime": "2020-08-23T09:00:00+02:00", "list": 456, "created": "2020-08-23T09:00:00+02:00", "auto_checked_in": false, "gate": null, "device": 1, "device_id": 1, "type": "entry" } An unauthorized user usually has no way to match these IDs (position) back to individual people. Affected versions
2026.3.0
2026.2.0
2025.10.0
2025.10.1
2025.10.2
2026.1.0
2026.1.1
Fixed in
2026.1.2
2026.2.1
2026.3.1
References Updated Jun 08, 2026 · Source: OSV.dev | ||
2025.9.4
patch
1 CVE
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2025.10.2
patch
2 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5600
GHSA-wr8q-c73g-m7gp
PYSEC-2026-111
Apr 08, 2026
pretix: API leaks check-in data between events of the same organizer
Medium
Network
Low
High
None
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those they should not have access to. These records contain information on the time and result of every ticket scan as well as the ID of the matched ticket. Example: { "id": 123, "successful": true, "error_reason": null, "error_explanation": null, "position": 321, "datetime": "2020-08-23T09:00:00+02:00", "list": 456, "created": "2020-08-23T09:00:00+02:00", "auto_checked_in": false, "gate": null, "device": 1, "device_id": 1, "type": "entry" } An unauthorized user usually has no way to match these IDs (position) back to individual people. Affected versions
2026.3.0
2026.2.0
2025.10.0
2025.10.1
2025.10.2
2026.1.0
2026.1.1
Fixed in
2026.1.2
2026.2.1
2026.3.1
References Updated Jun 08, 2026 · Source: OSV.dev | ||
2026.1.1
patch
2 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5600
GHSA-wr8q-c73g-m7gp
PYSEC-2026-111
Apr 08, 2026
pretix: API leaks check-in data between events of the same organizer
Medium
Network
Low
High
None
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those they should not have access to. These records contain information on the time and result of every ticket scan as well as the ID of the matched ticket. Example: { "id": 123, "successful": true, "error_reason": null, "error_explanation": null, "position": 321, "datetime": "2020-08-23T09:00:00+02:00", "list": 456, "created": "2020-08-23T09:00:00+02:00", "auto_checked_in": false, "gate": null, "device": 1, "device_id": 1, "type": "entry" } An unauthorized user usually has no way to match these IDs (position) back to individual people. Affected versions
2026.3.0
2026.2.0
2025.10.0
2025.10.1
2025.10.2
2026.1.0
2026.1.1
Fixed in
2026.1.2
2026.2.1
2026.3.1
References Updated Jun 08, 2026 · Source: OSV.dev | ||
2026.1.0
major
3 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5600
GHSA-wr8q-c73g-m7gp
PYSEC-2026-111
Apr 08, 2026
pretix: API leaks check-in data between events of the same organizer
Medium
Network
Low
High
None
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those they should not have access to. These records contain information on the time and result of every ticket scan as well as the ID of the matched ticket. Example: { "id": 123, "successful": true, "error_reason": null, "error_explanation": null, "position": 321, "datetime": "2020-08-23T09:00:00+02:00", "list": 456, "created": "2020-08-23T09:00:00+02:00", "auto_checked_in": false, "gate": null, "device": 1, "device_id": 1, "type": "entry" } An unauthorized user usually has no way to match these IDs (position) back to individual people. Affected versions
2026.3.0
2026.2.0
2025.10.0
2025.10.1
2025.10.2
2026.1.0
2026.1.1
Fixed in
2026.1.2
2026.2.1
2026.3.1
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev | ||
2025.8.3
patch
2 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev | ||
2025.9.3
patch
2 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev | ||
2025.10.1
patch
3 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-5600
GHSA-wr8q-c73g-m7gp
PYSEC-2026-111
Apr 08, 2026
pretix: API leaks check-in data between events of the same organizer
Medium
Network
Low
High
None
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those they should not have access to. These records contain information on the time and result of every ticket scan as well as the ID of the matched ticket. Example: { "id": 123, "successful": true, "error_reason": null, "error_explanation": null, "position": 321, "datetime": "2020-08-23T09:00:00+02:00", "list": 456, "created": "2020-08-23T09:00:00+02:00", "auto_checked_in": false, "gate": null, "device": 1, "device_id": 1, "type": "entry" } An unauthorized user usually has no way to match these IDs (position) back to individual people. Affected versions
2026.3.0
2026.2.0
2025.10.0
2025.10.1
2025.10.2
2026.1.0
2026.1.1
Fixed in
2026.1.2
2026.2.1
2026.3.1
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev | ||
2025.10.0
minor
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-5600
GHSA-wr8q-c73g-m7gp
PYSEC-2026-111
Apr 08, 2026
pretix: API leaks check-in data between events of the same organizer
Medium
Network
Low
High
None
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those they should not have access to. These records contain information on the time and result of every ticket scan as well as the ID of the matched ticket. Example: { "id": 123, "successful": true, "error_reason": null, "error_explanation": null, "position": 321, "datetime": "2020-08-23T09:00:00+02:00", "list": 456, "created": "2020-08-23T09:00:00+02:00", "auto_checked_in": false, "gate": null, "device": 1, "device_id": 1, "type": "entry" } An unauthorized user usually has no way to match these IDs (position) back to individual people. Affected versions
2026.3.0
2026.2.0
2025.10.0
2025.10.1
2025.10.2
2026.1.0
2026.1.1
Fixed in
2026.1.2
2026.2.1
2026.3.1
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev | ||
2025.9.2
patch
4 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev | ||
2025.8.2
patch
4 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev | ||
2025.7.3
patch
4 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev | ||
2025.9.1
patch
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2025.8.1
patch
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2025.7.2
patch
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2025.9.0
minor
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2025.8.0
minor
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2025.7.1
patch
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2025.7.0
minor
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2025.6.0
minor
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2025.5.0
minor
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2025.4.0
minor
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2025.3.0
minor
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2025.2.0
minor
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2025.1.0
major
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev | ||
2024.11.0
minor
5 CVEs
CVE-2026-9712
PYSEC-2026-2960
GHSA-72p9-6vv6-gvqh
Jul 13, 2026
pretix vulnerable to Authorization Bypass Through User-Controlled Key
High
Network
Low
Low
None
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the API client can then request the actual file for download. The same kind of UUID is used in other places in pretix when temporary files are generated for internal use or download. One remaining API endpoint, however, wrongfully did not verify if the UUID used for download actually belongs to a file that is supposed to be downloadable and belongs to the correct user. In reality, this is hard to exploit because an attacker would need to have access to a valid UUID for the file they desire which is unlikely to happen without a separate security problem giving them access to logs etc. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 174 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.10.1
2025.10.2
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
2025.9.4
2026.1.0
2026.1.1
2026.1.2
2026.2.0
2026.2.1
2026.2.2
2026.3.0
2026.3.1
2026.3.2
2026.3.3
2026.3.4
2026.3.5.post1
2026.4.0
2026.4.1
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2026.4.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-14881
PYSEC-2026-1803
GHSA-r2h2-g46h-8mx8
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-14882
PYSEC-2026-1802
GHSA-pmjj-h5jm-vxh4
Jul 07, 2026
pretix has Broken Access Control Allowing Cross-User File Access via UUID
High
Network
Low
Low
None
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
+ 155 more Show less
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.10.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.9.0
2025.9.1
2025.9.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.8.3
2025.9.3
2025.10.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-2415
GHSA-r8p8-qw9w-j9qv
PYSEC-2026-110
Feb 16, 2026
pretix unsafely evaluates variables in emails
High
Network
High
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
Out of caution, pretix recommend that you rotate all passwords and API keys contained in your pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. Affected versions
2026.1.0
2025.10.0
2025.10.1
1.0.0
1.0.0b1
1.0.0b2
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
+ 159 more Show less
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
2025.7.3
2025.8.0
2025.8.1
2025.8.2
2025.8.3
2025.9.0
2025.9.1
2025.9.2
2025.9.3
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
Fixed in
2025.9.4
2025.10.2
2026.1.1
References
Updated May 20, 2026 · Source: OSV.dev
CVE-2025-13742
GHSA-2mm6-624x-fqrr
PYSEC-2025-154
Nov 27, 2025
pretix has Email Content Injection Through Maliciously Formatted Names
Low
Network
Low
None
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. Affected versions
1.0.0
1.1.0
1.1.1
1.1.2
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
+ 149 more Show less
1.13.1
1.14.0
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.2.0
1.2.1.post2
1.2.2
1.3.0
1.3.0.post1
1.3.1
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.7.1
1.7.2
1.8.0
1.8.1
1.9.0
1.9.1
2.0.0
2.1.0
2.2.0
2.3.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.8.2
2023.10.0
2023.10.1.post1
2023.10.2
2023.6.0
2023.6.1
2023.6.3
2023.7.0
2023.7.1
2023.7.3
2023.8.0
2023.8.1
2023.9.0
2023.9.1
2024.1.0
2024.1.1
2024.10.0
2024.11.0
2024.2.0
2024.3.0
2024.4.0
2024.5.0
2024.5.1
2024.6.0
2024.6.1
2024.7.0
2024.7.1
2024.8.0
2024.9.0
2025.1.0
2025.2.0
2025.3.0
2025.4.0
2025.5.0
2025.6.0
2025.7.0
2025.7.1
2025.7.2
3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.11.1
3.12.0
3.12.1
3.13.0
3.13.1
3.14.0
3.14.1
3.14.2
3.15.0
3.16.0
3.17.1
3.17.2
3.18.0
3.2.0
3.3.0
3.4.0
3.5.0
3.6.0
3.6.0.post1
3.7.0
3.8.0
3.9.0
4.0.0
4.1.0
4.10.0
4.10.1
4.11.0
4.11.1
4.12.0
4.13.0
4.13.1
4.14.0
4.14.0.dev0
4.15.0
4.15.0.dev0
4.15.1
4.16.0
4.16.1
4.17.0
4.17.1
4.18.0
4.18.1
4.18.2
4.18.2.post1
4.19.0
4.2.0
4.20.0
4.20.1
4.20.2.post1
4.20.4
4.3.0
4.3.1
4.4.0
4.4.1
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.7.0
4.7.1
4.8.0
4.9.0
4.9.1
2025.8.0
2025.8.1
2025.9.0
2025.9.1
Fixed in
2025.7.3
2025.8.2
2025.9.2
References
Updated Jun 09, 2026 · Source: OSV.dev |