Search/CVE-2026-13225
CVE

CVE-2026-13225

Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization on the confirmation page for individual tickets in that order.

CVSS v3.1
EPSS
0.44%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Aug 26, 2026
0.10pp
0.34% → 0.44% over 2 tracked changes
Connections
1 relationships
Timeline
disclosure → media coverage
Jun 25, 2026
Disclosure — published as a CVE record.