CVE-2026-57532 Details
Description
Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one backend user to inject JavaScript into the browser context of another backend user. Due to requirements of the PDF rendering and editing libraries used, this is one of the few pages in our backend that do not have a strong Content-Security-Policy that would render this capability useless for most scenarios.
A stored cross-site scripting vulnerability has been identified in the PDF layout editor of Pretix. This issue arises because malicious HTML content in the layout specification of PDF tickets or badges is executed when the editor is opened in a browser. As a result, one backend user could potentially inject JavaScript into the browser context of another backend user. This vulnerability exists in all currently supported versions of Pretix, except for the fixed versions 2026.5.2, 2026.4.4, and 2026.3.4.
Users are advised to update to Pretix versions 2026.5.2, 2026.4.4, or 2026.3.4. For those using the Pretix Pages plugin, version 1.6.4 is available. If using the Pretix Hosted service, no action is needed as the vulnerability has already been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://pretix.eu/about/en/blog/20260625-release-2026-5-2/ | rami.io | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-80 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | rami.io |
Affected Products
| Product | Versions |
|---|---|
| pretix | >= 2026, < 2026.5.2 >= 2026, < 2026.4.4 >= 2026, < 2026.3.4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | rami.io |
Volerion