pretix Vulnerabilities and Affected Products
Vulnerabilities associated with pretix-oppwa.
Products
Clear product- pretix12 vulnerabilities
- Venueless5 vulnerabilities
- pretix-oppwa3 vulnerabilities
- pretix-mollie2 vulnerabilities
- pretix-bitpay1 vulnerability
- pretix-computop1 vulnerability
- pretix-digital1 vulnerability
- pretix-doistep1 vulnerability
- pretix-newsletter1 vulnerability
- pretix-offlinesales1 vulnerability
- pretix-pages1 vulnerability
- pretix-payone1 vulnerability
- pretix-saferpay1 vulnerability
- pretix-secuconnect1 vulnerability
- pretix-sofort1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-13602HIGH | Session takeover vulnerabilityWe found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: * The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay contain a code path that is intended for the transport of session parameters from a tab with isolated cookies (e.g. in the pretix widget) to a new ta… | CVSS7.7v4.0 | EPSS0.271% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-13603CRITICAL | SSRF with API key leak in pretix-oppwaThe payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially others based on Oppwa's technology. The integration of Oppwa, following their official documentation, includes a step where the user is redirected from the payment provider back to our system with a query parameter like ?resourcePath=/v1/checkouts/{checkoutId}/payment in the URL. Our system is then supposed to fetch the status of the transaction from the URL given by baseUrl + … | CVSS9.0v4.0 | EPSS0.288% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-13222MEDIUM | Insufficient validation of payment status in pretix-oppwaOur payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment. CWE-841Jun 25, 2026 | CVSS6.3v4.0 | EPSS0.257% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |