CVE-2025-14882: Pretix Pretix-Offlinesales

Low severity, CVSS 3.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID only.

Affected products

  • Pretix Pretix-Offlinesales: from 1.12.0, up to and including 1.12.1

Published 2025-12-19. Last modified 2026-06-17.