CVE-2026-18029
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
28/07/2026
Last modified:
30/07/2026
Description
Our payment integration with GiroCheckout did not properly validate <br />
payment status responses. An attacker could use a successful payment <br />
status response from one payment and supply it to the system for a <br />
different payment, gaining access to multiple valid tickets with only <br />
one payment.
Impact
Base Score 4.0
6.30
Severity 4.0
MEDIUM



