PostHog is a product analytics and feature management platform with a relatively narrow product footprint centered on its core analytics service and JavaScript SDK. The recurring vulnerability surface reflects the vendor's role as a web-facing application handling user input and performing server-side request operations: vulnerabilities cluster around server-side request forgery, cross-site scripting, SQL injection, and open-redirect conditions that are characteristic of analytics and instrumentation platforms. Live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Posthog over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1520HIGH PostHog ClickHouse Table Functions SQL Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected ins | Apr 23, 2025 | 8.0 | 25 | NO | NO |
CVE-2025-1521MEDIUM PostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on aff | Apr 23, 2025 | 6.5 | 24 | NO | NO |
CVE-2024-9710HIGH PostHog database_schema Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected i | Nov 22, 2024 | 8.3 | 23 | NO | NO |
CVE-2022-0645MEDIUM Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1. | Apr 19, 2022 | 6.1 | 22 | NO | NO |
CVE-2025-1522MEDIUM PostHog database_schema Server-Side Request Forgery Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected i | Apr 23, 2025 | 6.5 | 20 | NO | NO |
CVE-2023-32325MEDIUM PostHog-js is a library to interface with the PostHog analytics tool. Versions prior to 1.57.2 have the potential for cross-site scripting. Problem has been patched in 1.57.2. User | May 27, 2023 | 6.1 | 17 | NO | NO |
CVE-2023-46746MEDIUM PostHog provides open-source product analytics, session recording, feature flagging and A/B testing that you can self-host. A server-side request forgery (SSRF), which can only be | Dec 1, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Posthog.
Media articles that mention a CVE ID that affects a product developed by Posthog — matched by CVE ID, not by vendor name.