CVE-2026-13225

Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization on the confirmation page for individual tickets in that order.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-06-25 15:16

Updated : 2026-06-25 16:16


NVD link : CVE-2026-13225

Mitre link : CVE-2026-13225

CVE.ORG link : CVE-2026-13225


JSON object : View

Products Affected

No product.

CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)