๐Ÿ” CVE Alert

CVE-2026-82838

UNKNOWN 0.0

Default webserver configuration with incorrect CSP

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The default docker image shipped for Venueless did not properly ensure that uploaded SVG files could not be delivered with executable JavaScript content. A valid Content Security Policy is now set.

CWE CWE-80
Vendor pretix
Product venueless
Published Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for pretix venueless

Be the first to know when new unknown vulnerabilities affecting pretix venueless are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

pretix / venueless
0 < 7dff888

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/venueless/venueless/security/advisories/GHSA-38wh-hqvm-xgfc

Credits

Vignesh M