VendorsGitroompostizany version
Vulnerabilities

Gitroom Postiz any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-42298
Postiz: Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev
Published 2026-05-08 · Analyzed
10.0EPSS 0.008
CVE-2026-40487
Postiz Has Unrestricted File Upload via MIME Type Spoofing that Leads to Stored XSS
Published 2026-04-18 · Analyzed
9.0EPSS 0.003
CVE-2026-34577
Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check
Published 2026-04-02 · Analyzed
8.6EPSS 0.005
CVE-2026-34576
Postiz: SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata
Published 2026-04-02 · Analyzed
8.3EPSS 0.004
CVE-2026-40168
Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream
Published 2026-04-10 · Analyzed
8.2EPSS 0.005
CVE-2026-34590
Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validation
Published 2026-04-02 · Analyzed
5.4EPSS 0.003