CVE-2026-82838

Summary

The default docker image shipped for Venueless did not properly ensure that uploaded SVG files could not be delivered with executable JavaScript content. A valid Content Security Policy is now set.

Affected Software

VendorProductVersion RangeStatus
pretixvenueless0 < 7dff888affected

Weaknesses

  • CWE-80: CWE-80 Improper neutralization of Script-Related HTML tags in a web page (basic XSS)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References