Security: gitroomhq/postiz-app
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Insufficient verification of lifetime-deal redemption codes allows forgery of permanent paid subscriptionsGHSA-5m7p-wphr-xjp7 published
Aug 6, 2026 by postiz-agentModerate -
Unauthenticated arbitrary file read via /uploads path traversal (URL-encoded separators) leading to instance takeoverGHSA-4hgh-5rhf-4qpm published
Aug 7, 2026 by postiz-agentCritical -
Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhookGHSA-j7rp-5mgj-qgg9 published
May 23, 2026 by postiz-agentHigh -
Unauthenticated billing-enforcement bypass via /public/modify-subscriptionGHSA-v4wr-4j8g-4hfj published
May 22, 2026 by postiz-agentModerate -
SUPERADMIN takeover via Skool-provider JWT forgeryGHSA-j77w-h625-56q2 published
May 22, 2026 by postiz-agentCritical -
Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.devGHSA-v975-9h5p-xhm4 published
Apr 22, 2026 by egelhausCritical -
Postiz stored XSS in public preview pageGHSA-hhxq-3wg7-4rj8 published
Apr 27, 2026 by postiz-agentHigh -
TOCTOU DNS rebinding bypasses all SSRF URL validation pathsGHSA-f7jj-p389-4w45 published
Apr 28, 2026 by postiz-agentModerate -
Unrestricted File Upload via MIME Type Spoofing Leads to Stored XSSGHSA-44wg-r34q-hvfx published
Apr 12, 2026 by egelhausCritical -
Server-Side Request Forgery via Redirect Bypass in /api/public/streamGHSA-34w8-5j2v-h6ww published
Apr 9, 2026 by egelhausHigh