Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-57532 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one backend user to inject JavaScript into the browser context of another backend user. Due to requirements of the PDF rendering and editing libraries used, this is one of the few pages in our backend that do not have a strong Content-Security-Policy that would render this capability useless for most scenarios.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://pretix.eu/about/en/blog/20260625-release-2026-5-2/ rami.ioAdvisoryBundleRemedyVendor

Weakness Enumeration

CWE-IDCWE NameSource
CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)rami.io

Affected Products

ProductVersions
pretix
>= 2026, < 2026.5.2
>= 2026, < 2026.4.4
>= 2026, < 2026.3.4

CPE

  • cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*:*

Remediation

Change History

2 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-57532
NVD Published Date:
Jun 25, 2026
NVD Last Modified:
Jun 25, 2026
Source:
rami.io
CVE-2026-57532 Details - Not Deferred