PT-2026-34723 · Pretalx · Pretalx
Elad Meged
·
Published
2026-04-18
·
Updated
2026-06-02
·
CVE-2026-41241
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
pretalx versions prior to 2026.1.0
Description
The organiser search in the backend renders submission titles, speaker display names, and user names or emails into the result dropdown using innerHTML string interpolation. This allows a user who controls these fields to inject HTML or JavaScript that executes in the browser of an organiser when a search query matches the malicious record.
Recommendations
Update to version 2026.1.0.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pretalx