pretix GmbH Vulnerabilities and Affected Products
Vulnerabilities associated with pretix-girosolution.
Products
Clear product- pretix1 vulnerability
- pretix-girosolution1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-18029MEDIUM | Insufficient validation of payment status in pretix-girosolutionOur payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment. CWE-841Jul 28, 2026 | CVSS6.3v4.0 | EPSS0.207% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |