Gitroom
Gitroom Postiz: vulnerabilidades y CVE
Gitroom Postiz tiene 14 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses13
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-94456 | Crítica (9.1) | 0.52% | — | 22 sept 2026 | Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API… |
| CVE-2026-19264 | Crítica (9.3) | 1.0% | — | 7 ago 2026 | Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining… |
| CVE-2026-48799 | Alta (7.7) | 0.22% | — | 15 jul 2026 | Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from… |
| CVE-2026-48783 | Media (4.8) | 0.20% | — | 17 jun 2026 | Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced… |
| CVE-2026-48781 | Crítica (9.9) | 0.28% | — | 17 jun 2026 | Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth… |
| CVE-2026-42556 | Crítica (9) | 0.44% | — | 8 may 2026 | Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request and… |
| CVE-2026-42346 | Media (6.5) | 0.36% | — | 8 may 2026 | Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added in v2.21.4–v2.21.6 share a fundamental TOCTOU (Time-of-Check-Time-of-Use) vulnerability:… |
| CVE-2026-42298 | Crítica (9.8) | 0.81% | — | 8 may 2026 | Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated… |
| CVE-2026-40487 | Crítica (9) | 0.26% | — | 18 abr 2026 | Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by… |
| CVE-2026-40168 | Alta (8.2) | 0.52% | — | 10 abr 2026 | Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application validates the initially supplied URL and blocks direct private/internal… |
| CVE-2026-34590 | Media (5.4) | 0.33% | — | 2 abr 2026 | Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhooks uses WebhooksDto which validates the url field with only @IsUrl() (format check), missing the… |
| CVE-2026-34577 | Alta (8.6) | 0.53% | — | 2 abr 2026 | Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicController accepts a user-supplied url query parameter and proxies the full HTTP response back to the… |
| CVE-2026-34576 | Alta (8.3) | 0.37% | — | 2 abr 2026 | Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the POST /public/v1/upload-from-url endpoint accepts a user-supplied URL and fetches it server-side using axios.get() with no SSRF protections. The… |
| CVE-2025-53641 | Alta (8.2) | 0.26% | — | 11 jul 2025 | Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker to inject arbitrary HTTP headers into the middleware pipeline. This flaw enables a server-side… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.