Postiz App
/gitroomhq/postiz/postiz-app
PublicReport a vulnerability
Published advisories
Atom feedPSA-2026-04-M1S02026-04-28TOCTOU DNS rebinding bypasses all SSRF URL validation paths
TOCTOU DNS rebinding bypasses all SSRF URL validation paths
MediumPSA-2026-T0E4W02026-04-27Postiz stored XSS in public preview page
Postiz stored XSS in public preview page
HighPSA-2026-04-1YDY2026-04-24Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev
CriticalPSA-2026-04-6EZ52026-04-22Server-Side Request Forgery via Redirect Bypass in /api/public/stream
Server-Side Request Forgery via Redirect Bypass in /api/public/stream
HighPSA-2026-04-5MVG2026-04-19Unrestricted File Upload via MIME Type Spoofing Leads to Stored XSS
Unrestricted File Upload via MIME Type Spoofing Leads to Stored XSS
CriticalPSA-2026-04-HVBM2026-04-19SSRF via Webhook Creation Endpoint Missing URL Safety Validation
SSRF via Webhook Creation Endpoint Missing URL Safety Validation
MediumPSA-2026-04-KT4W2026-04-19SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata
SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata
MediumPSA-2026-04-422G2026-04-19Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check
Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check
HighPSA-2026-04-SRGA2026-04-19High-Severity SSRF in Postiz App
High-Severity SSRF in Postiz App
HighPSA-2026-04-ZR1M2026-04-19Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)
Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)
HighPSA-2026-04-PY6V2026-04-19Header mutation in middleware facilitates SSRF
Header mutation in middleware facilitates SSRF
High