Signal
Stored XSS flaw in pretalx conference software allowed guaranteed talk acceptance
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-05-27 12:00 UTCUpdated 2026-05-27 14:30 UTC
rss
vulnerabilitysecurity_toolingincident_response
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
A stored cross-site scripting (XSS) vulnerability (CVE-2026-41241) in pretalx, a widely used open source conference call-for-papers (CFP) management tool, enabled attackers to hijack organizer sessions and manipulate talk submissions.
Entities
pretalxElad Meged
Score total
0.99
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- The vulnerability was patched recently in April 2026, making awareness and updates urgent.
- Security researchers publicly disclosed the flaw and its impact this month.
- Conferences planning upcoming CFP cycles should verify they use patched pretalx versions.
Why it matters
- Pretalx is widely used by tech conferences to manage speaker submissions, so the flaw could impact many events.
- Attackers could manipulate conference schedules and speaker lineups by exploiting this vulnerability.
- The incident highlights risks in open source event management tools and the importance of timely patching.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- Stored XSS vulnerability in pretalx allowed attackers to hijack organizer sessions and approve talks.
How sources frame it
- Theregister_security: neutral
- SecurityWeek: neutral
All evidence
All evidence
Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate
SecurityWeek · securityweek.com · 2026-05-27 14:30 UTC
How to guarantee a speaker gig: Hack the system. Literally
theregister_security · theregister.com · 2026-05-27 12:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- SecurityWeek (1)
- theregister_security (1)
Top origin domains (this list)
- securityweek.com (1)
- theregister.com (1)