PT-2026-34723 · Pretalx · Pretalx

Elad Meged

·

Published

2026-04-18

·

Updated

2026-06-02

·

CVE-2026-41241

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions pretalx versions prior to 2026.1.0
Description The organiser search in the backend renders submission titles, speaker display names, and user names or emails into the result dropdown using innerHTML string interpolation. This allows a user who controls these fields to inject HTML or JavaScript that executes in the browser of an organiser when a search query matches the malicious record.
Recommendations Update to version 2026.1.0.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41241
GHSA-CJCX-JFP2-F7M2
PYSEC-2026-108

Affected Products

Pretalx