CVE-2026-101267: fallo de gravedad baja en pretix
Revenue information leak
Publicada el
8Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 2.7epss 0.2%
probabilidad de explotación
0.2%top 86% de las CVE
explotación observada
noninguna fuente lo reporta
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:U
Productos afectados
pretix · pretixCVEs relacionadas — pretix
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-13225MEDIUMStored XSS in ticket confirmation pageEPSS 0.4%CVE-2026-57532HIGHCVE-2026-57532EPSS 0.4%CVE-2026-57535LOWCVE-2026-57535EPSS 0.4%CVE-2026-13602HIGHSession takeover vulnerabilityEPSS 0.4%CVE-2026-9712LOWInsecure direct object referenceEPSS 0.4%CVE-2024-8113HIGHStored XSS in Placeholder Samples in Mail PreviewEPSS 0.3%