cbcvebase.
CVE-2025-13742
published 2025-11-27

CVE-2025-13742: Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be…

PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.15%
5.0th percentile
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing.

Affected

10 ranges
VendorProductVersion rangeFixed in
pretixpretix
pretixpretix
pretixpretix>= 1.0.0 < 2025.7.02025.7.0
pretixpretix>= 1.0.0 < 2025.7.22025.7.2
pretixpretix>= 1.0.0 < 2025.7.32025.7.3
pretixpretix>= 2025.7.0 < 2025.8.02025.8.0
pretixpretix>= 2025.8.0 < 2025.9.02025.9.0
pretixpretix>= 2025.8.0 < 2025.8.22025.8.2
pretixpretix>= 2025.9.0 < 2025.10.02025.10.0
pretixpretix>= 2025.9.0 < 2025.9.22025.9.2

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.02.4LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:L/SC:N/SI:L/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.