FOSDEM A.I CyberSecurity Scoring
FOSDEM
Company Information
Website:https://fosdem.org
Employees number:8
Number of followers:7,938
NAICS:5112
Industry Type:Software Development
Homepage:fosdem.org
FOSDEM Risk Score (AI oriented)
Between 700 and 749
FOSDEMSoftware Development
Updated:
27/05/2026
27/05/2026
732/1000
Moderate
Ba
FOSDEM Global Score (TPRM)
xxxx
FOSDEMSoftware Development
Score locked

FOSDEMModerate
Current Score
732Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
732
MAY 2026
732
APRIL 2026
749
Cyber Attack
01 Apr 2026 • FOSDEM
TROOPERS, HEXACON, FOSDEM and Recon: How to guarantee a speaker gig: Hack the system. Literally
Security Researcher Exploits XSS Flaw in pretalx to Auto-Accept Conference Talks
731
CRITICAL-18
HEXFOSPRETRO1779884685
Security Researcher Exploits XSS Flaw in pretalx to Auto-Accept Conference Talks
A security researcher discovered a critical stored cross-site scripting (XSS) vulnerability (CVE-2026-41241) in pretalx, an open-source tool widely used by tech conferences to manage speaker submissions and schedules. The flaw allowed attackers to inject malicious JavaScript into searchable fields such as submission titles, speaker names, or email addresses which would execute when an organizer conducted a search.
Once triggered, the payload could access the organizer’s CSRF token, enabling authenticated requests on their behalf, including data modification or exfiltration. The vulnerability was patched in pretalx 2026.1.0 in April.
Elad Meged, founding engineer at AI security startup Novee, identified the flaw while preparing conference submissions. Noticing that multiple events including OffensiveCon, TROOPERS, FOSDEM, HEXACON, and Recon used the same pretalx-based system, he tested the exploit by submitting 40 automated proposals under the intentionally bland title "Securing Modern Web Apps." All were accepted, demonstrating the flaw’s potential for abuse.
Meged’s team validated the exploit in a local environment, avoiding live testing on public instances. While no active exploitation was detected, the vulnerability posed a serious risk: organizer-level access could have enabled attackers to alter submissions, impersonate staff, or launch phishing campaigns from trusted conference systems.
The research leveraged AI-assisted tools to scale discovery, fingerprinting vulnerable deployments, and adapt exploit paths across different pretalx versions. Meged emphasized that while the core vulnerability was simple to exploit, automated agentic systems were crucial for mapping internet-wide exposure and managing responsible disclosure.
Tobias Kunze, pretalx’s creator, confirmed receiving 11 security findings from Meged, classifying one as critical and others as non-vulnerability bugs with fixes. The disclosure process was described as professional and collaborative. No evidence suggests the flaw was exploited before Novee’s report.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
749
FEBRUARY 2026
749
JANUARY 2026
749
DECEMBER 2025
749
NOVEMBER 2025
749
OCTOBER 2025
749
SEPTEMBER 2025
749
AUGUST 2025
749
JULY 2025
749
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for FOSDEM ??
What was FOSDEM's A.I Rankiteo Cyber Score in May 2026 ??
What was FOSDEM's A.I Rankiteo Cyber Score in April 2026 ??
What was FOSDEM's A.I Rankiteo Cyber Score in March 2026 ??
What was FOSDEM's A.I Rankiteo Cyber Score in February 2026 ??
What was FOSDEM's A.I Rankiteo Cyber Score in January 2026 ??
What was FOSDEM's A.I Rankiteo Cyber Score in December 2025 ??
What was FOSDEM's A.I Rankiteo Cyber Score in November 2025 ??
What was FOSDEM's A.I Rankiteo Cyber Score in October 2025 ??
What was FOSDEM's A.I Rankiteo Cyber Score in September 2025 ??
What was FOSDEM's A.I Rankiteo Cyber Score in August 2025 ??
What was FOSDEM's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on FOSDEM's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with FOSDEM ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view FOSDEM's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?