Postiz App
/gitroomhq/postiz/postiz-app
Published advisories
Atom feedPSA-2026-Q3TCPK2026-05-23Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook
MediumPSA-2026-WWFR8X2026-05-22Unauthenticated billing-enforcement bypass via /public/modify-subscription
MediumPSA-2026-2CAQ962026-05-22SUPERADMIN takeover via Skool-provider JWT forgery
Attackers can exploit the skool-provider JWT sign process to generate a JWT token with isSuperAdmin: true
HighPSA-2026-04-M1S02026-04-28TOCTOU DNS rebinding bypasses all SSRF URL validation paths
TOCTOU DNS rebinding bypasses all SSRF URL validation paths
MediumPSA-2026-T0E4W02026-04-27Postiz stored XSS in public preview page
Postiz stored XSS in public preview page
HighPSA-2026-04-1YDY2026-04-24Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev
CriticalPSA-2026-04-6EZ52026-04-22Server-Side Request Forgery via Redirect Bypass in /api/public/stream
Server-Side Request Forgery via Redirect Bypass in /api/public/stream
HighPSA-2026-04-5MVG2026-04-19Unrestricted File Upload via MIME Type Spoofing Leads to Stored XSS
Unrestricted File Upload via MIME Type Spoofing Leads to Stored XSS
CriticalPSA-2026-04-HVBM2026-04-19SSRF via Webhook Creation Endpoint Missing URL Safety Validation
SSRF via Webhook Creation Endpoint Missing URL Safety Validation
MediumPSA-2026-04-KT4W2026-04-19SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata
SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata
MediumPSA-2026-04-422G2026-04-19Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check
Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check
HighPSA-2026-04-SRGA2026-04-19High-Severity SSRF in Postiz App
High-Severity SSRF in Postiz App
HighPSA-2026-04-ZR1M2026-04-19Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)
Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)
HighPSA-2026-04-PY6V2026-04-19Header mutation in middleware facilitates SSRF
Header mutation in middleware facilitates SSRF
High