Skip to content
PSA-2026-G1CT26GCVE-125-2026-G1CT26August 15, 2026
5.4 Medium

DMARC not enabled for postiz.com

Postiz has not enabled DMARC on their primary domain, resulting to email forgery.

Affected (1)

  • GitroomHQpostiz-cloud
    • ≥ 0Fixed in 0.1Affected

    All other versions: Affected

Overview

Postiz is an open-source social media scheduler. This advisory is exclusively for the Postiz Cloud environment. The DMARC record of 'postiz.com' has been set to 'none', resulting it to be disabled. This would allow forgery or our email's, with no Spam-Filter blocking it on the client-side.

Severity

CVSS v3
5.4 Medium
5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low

Weaknesses (1)

References (1)

Credits (3)

  • Muhammad Waqas
    Reporter · @Waqas-105
  • Enno Gelhaus
    Coordinator · @egelhaus
  • Nevo David
    Remediation developer · @nevo-david

Context

Impacts

  • Anybody was able to send emails from any postiz.com E-Mail, resulting in loss of trust to Postiz.

© 2026 Gelhaus Solutions