← Vulnerability feed

Vulnerability record · CVE-2024-8113 · published 23 August 2024

CVE-2024-8113: Pretix cross-site scripting vulnerability

Pretix · Pretix

Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The default Content Security Policy of pretix prevents execution of attacker-provided scripts, making exploitation unlikely. However, combined with a CSP bypass (which is not currently known) the vulnerability could be used to impersonate other organizers or staff users.

7.2 CVSS 4.0 High EPSS 0.32% · top 77.1% CWE-79 · Cross-site scripting
7.2CVSS 4.0 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The default Content Security Policy of pretix prevents execution of attacker-provided scripts, making exploitation unlikely. However, combined with a CSP bypass (which is not currently known) the vulnerability could be used to impersonate other organizers or staff users.

CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-8113 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-27447Pretix improper input validation vulnerabilitypretix before 2024.1.1 mishandles file validation.EPSS 0.82%7.5CVE-2026-2415Pretix vulnerabilityEmails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will…EPSS 0.25%7.5CVE-2026-2451Pretix double opt in step vulnerabilityEmails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will…EPSS 0.27%7.5CVE-2026-2452Pretix newsletters vulnerabilityEmails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will…EPSS 0.27%5.5CVE-2026-5600Pretix vulnerabilityA new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events b…EPSS 0.31%2.4CVE-2025-13742Pretix vulnerabilityEmails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will…EPSS 0.18%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed

Source: NIST National Vulnerability Database (record CVE-2024-8113), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.