← Back

Pretix

pretix

Vendor: Rami • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rami
1Pretix
Jun 17, 2026
Oct 2, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead...Show more
An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead to IP address spoofing by users of the application.Show less
1Rami
1Pretix
Jun 17, 2026
Sep 29, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
pretix before 2023.7.2 allows Pillow to parse EPS files.
1Rami
1Pretix
Jun 17, 2026
Mar 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.