Postiz App
/gitroomhq/postiz/postiz-app
Published advisories
Atom feedPSA-2026-TH12B7August 7, 2026Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover
Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeover
CriticalPSA-2026-NWZN9JJune 22, 2026Insufficient verification of lifetime-deal redemption codes allows forgery of permanent paid subscriptions
MediumPSA-2026-Q3TCPKMay 23, 2026Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook
MediumPSA-2026-WWFR8XMay 22, 2026Unauthenticated billing-enforcement bypass via /public/modify-subscription
MediumPSA-2026-2CAQ96May 22, 2026SUPERADMIN takeover via Skool-provider JWT forgery
Attackers can exploit the skool-provider JWT sign process to generate a JWT token with isSuperAdmin: true
HighPSA-2026-04-M1S0April 28, 2026TOCTOU DNS rebinding bypasses all SSRF URL validation paths
TOCTOU DNS rebinding bypasses all SSRF URL validation paths
MediumPSA-2026-T0E4W0April 27, 2026Postiz stored XSS in public preview page
Postiz stored XSS in public preview page
HighPSA-2026-04-1YDYApril 24, 2026Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev
CriticalPSA-2026-04-6EZ5April 22, 2026Server-Side Request Forgery via Redirect Bypass in /api/public/stream
Server-Side Request Forgery via Redirect Bypass in /api/public/stream
HighPSA-2026-04-5MVGApril 19, 2026Unrestricted File Upload via MIME Type Spoofing Leads to Stored XSS
Unrestricted File Upload via MIME Type Spoofing Leads to Stored XSS
CriticalPSA-2026-04-HVBMApril 19, 2026SSRF via Webhook Creation Endpoint Missing URL Safety Validation
SSRF via Webhook Creation Endpoint Missing URL Safety Validation
MediumPSA-2026-04-KT4WApril 19, 2026SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata
SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata
MediumPSA-2026-04-422GApril 19, 2026Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check
Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check
HighPSA-2026-04-SRGAApril 19, 2026High-Severity SSRF in Postiz App
High-Severity SSRF in Postiz App
HighPSA-2026-04-ZR1MApril 19, 2026Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)
Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)
HighPSA-2026-04-PY6VApril 19, 2026Header mutation in middleware facilitates SSRF
Header mutation in middleware facilitates SSRF
High