pretix是德国pretix公司开源的一个票务系统。 pretix存在跨站脚本漏洞,该漏洞源于内容注入PDF渲染环境可包含HTML内容(包括img标签),如果这些图像的src属性指向URL,PDF渲染引擎将下载并显示该图像,从而泄露渲染服务器信息并可能在本地网络中形成SSRF向量。以下版本受到影响:2026.3.4之前版本、2026.4.4版本之前的2026.4.x版本和2026.5.2版本之前的2026.5.x版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57532 | pretix 跨站脚本漏洞 | |
| CVE-2026-57534 | Stored XSS in pretix-pages | |
| CVE-2026-57536 | Insufficient validation of payment status in pretix-mollie | |
| CVE-2026-57533 | pretix 跨站脚本漏洞 | |
| CVE-2026-13222 | Insufficient validation of payment status in pretix-oppwa | |
| CVE-2026-13225 | Stored XSS in ticket confirmation page | |
| CVE-2026-13223 | Insufficient validation of payment status in pretix-computop | |
| CVE-2026-13350 | venueless 授权问题漏洞 | |
| CVE-2026-13314 | Stored XSS in pretix-digital |
No comments yet