pretix是德国pretix公司开源的一个票务系统。 pretix存在跨站脚本漏洞,该漏洞源于PDF编辑器在浏览器中打开时未对PDF票证或徽章布局中的恶意HTML内容进行充分限制,导致后端用户可以向另一后端用户的浏览器环境注入JavaScript。以下版本受到影响:2026.3.4之前版本、2026.4.0至2026.4.4之前版本和2026.5.0至2026.5.2之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57535 | pretix 跨站脚本漏洞 | |
| CVE-2026-57534 | Stored XSS in pretix-pages | |
| CVE-2026-57536 | Insufficient validation of payment status in pretix-mollie | |
| CVE-2026-57533 | pretix 跨站脚本漏洞 | |
| CVE-2026-13222 | Insufficient validation of payment status in pretix-oppwa | |
| CVE-2026-13225 | Stored XSS in ticket confirmation page | |
| CVE-2026-13223 | Insufficient validation of payment status in pretix-computop | |
| CVE-2026-13350 | venueless 授权问题漏洞 | |
| CVE-2026-13314 | Stored XSS in pretix-digital |
No comments yet