Pretix Email Placeholder Injection Vulnerability Allowing Phishing Manipulation

Vulnerability

A vulnerability exists in Pretix email templates that allows for the injection of HTML or Markdown through placeholders. When names containing such formatting are used, the injected content is rendered as HTML in the final email. Although Pretix's strict allow list for HTML tags prevents this from being exploited for cross-site scripting or similar attacks, it can still be used to manipulate email content in a way that appears trustworthy, potentially leading to phishing attempts.

Impact

Exploitation of this vulnerability could result in phishing attacks, as it allows for the manipulation of email content to make it appear more credible.

Added: Nov 27, 2025, 11:20 AM
Updated: Nov 27, 2025, 11:20 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
7.6
remediation
7.7
relevance
1.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.