Postiz-App
Gitroomhq · 16 CVEs
Unauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API key
Sep 22, 2026
Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization codes, client secrets and organi…
Sep 22, 2026
Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover
Aug 7, 2026
Insufficient verification of lifetime-deal redemption codes allows forgery of permanent paid subscriptions
Aug 6, 2026
Postiz: Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook
Jul 15, 2026
Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription
Jun 16, 2026
Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
Jun 16, 2026
Postiz stored XSS in public preview page
May 8, 2026
Postiz: TOCTOU DNS rebinding bypasses all SSRF URL validation paths
May 8, 2026
Postiz: Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev
May 8, 2026
Postiz Has Unrestricted File Upload via MIME Type Spoofing that Leads to Stored XSS
Apr 18, 2026
Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream
Apr 10, 2026
Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validation
Apr 2, 2026
Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check
Apr 2, 2026
Postiz: SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata
Apr 2, 2026
Postiz allows header mutation in middleware facilitates resulting in SSRF
Jul 11, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-94455 | Unauthenticated /enterprise/create-user mints lifetime top-tier organizations and discloses their API key | HIGH | 0.26% | Sep 22, 2026 |
| CVE-2026-94456 | Unauthenticated recovery of the Math.random() state behind OAuth tokens, authorization codes, client secrets and organization API keys | CRITICAL | 0.52% | Sep 22, 2026 |
| CVE-2026-19264 | Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover | CRITICAL | 1.01% | Aug 7, 2026 |
| CVE-2026-19127 | Insufficient verification of lifetime-deal redemption codes allows forgery of permanent paid subscriptions | MEDIUM | 0.31% | Aug 6, 2026 |
| CVE-2026-48799 | Postiz: Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook | HIGH | 0.22% | Jul 15, 2026 |
| CVE-2026-48783 | Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription | MEDIUM | 0.20% | Jun 16, 2026 |
| CVE-2026-48781 | Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery | CRITICAL | 0.28% | Jun 16, 2026 |
| CVE-2026-42556 | Postiz stored XSS in public preview page | CRITICAL | 0.44% | May 8, 2026 |
| CVE-2026-42346 | Postiz: TOCTOU DNS rebinding bypasses all SSRF URL validation paths | MEDIUM | 0.36% | May 8, 2026 |
| CVE-2026-42298 | Postiz: Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev | CRITICAL | 0.81% | May 8, 2026 |
| CVE-2026-40487 | Postiz Has Unrestricted File Upload via MIME Type Spoofing that Leads to Stored XSS | CRITICAL | 0.26% | Apr 18, 2026 |
| CVE-2026-40168 | Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream | HIGH | 0.52% | Apr 10, 2026 |
| CVE-2026-34590 | Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validation | MEDIUM | 0.33% | Apr 2, 2026 |
| CVE-2026-34577 | Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check | HIGH | 0.53% | Apr 2, 2026 |
| CVE-2026-34576 | Postiz: SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata | HIGH | 0.37% | Apr 2, 2026 |
| CVE-2025-53641 | Postiz allows header mutation in middleware facilitates resulting in SSRF | HIGH | 0.26% | Jul 11, 2025 |
Showing 1 to 16 of 16 CVEs