Gitroom maintains Postiz, a social-media management and scheduling application that sits in the web-application tier of marketing and content-distribution workflows. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through input-handling and code-execution weakness classes including server-side request forgery, cross-site scripting, code injection, insufficient data authenticity verification, and unrestricted file uploads—attack surfaces characteristic of web applications that process user-supplied content and integrate with external APIs. Defenders should prioritize patching for this product, particularly in internet-facing deployments; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gitroom over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42298CRITICAL Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker- | May 8, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-42556CRITICAL Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by | May 8, 2026 | 9.0 | 34 | NO | NO |
CVE-2026-40487CRITICAL Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executa | Apr 18, 2026 | 9.0 | 31 | NO | NO |
CVE-2026-34577HIGH Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicController accepts a user-supplied url query parameter and proxies t | Apr 2, 2026 | 8.6 | 30 | NO | NO |
CVE-2026-40168HIGH Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application validates the initially supplied URL | Apr 10, 2026 | 8.2 | 28 | NO | NO |
CVE-2026-34576HIGH Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the POST /public/v1/upload-from-url endpoint accepts a user-supplied URL and fetches it server-side using axi | Apr 2, 2026 | 7.7 | 24 | NO | NO |
CVE-2026-34590MEDIUM Postiz is an AI social media scheduling tool. Prior to version 2.21.4, the POST /webhooks/ endpoint for creating webhooks uses WebhooksDto which validates the url field with only @ | Apr 2, 2026 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gitroom.
Media articles that mention a CVE ID that affects a product developed by Gitroom — matched by CVE ID, not by vendor name.