CVE-2025-14881: Pretix
Low severity, CVSS 3.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.
Affected products
- Pretix Pretix: from 1.0.0, before 2025.8.0 (fixed in 2025.8.0); from 2025.8.0, before 2025.9.0 (fixed in 2025.9.0); from 2025.9.0, before 2025.10.0 (fixed in 2025.10.0); from 2025.10.0, before 2025.11.0 (fixed in 2025.11.0)
Published 2025-12-19. Last modified 2026-06-17.