Roadiz is a headless content management system with a modestly sized vulnerability surface centered on its core development bundle. The observed weakness class involves server-side request forgery, reflecting a common risk in web applications that process external input or construct internal requests. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Roadiz over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33486MEDIUM Roadiz is a polymorphic content management system based on a node system that can handle many types of services. A vulnerability in roadiz/documents prior to versions 2.7.9, 2.6.28 | Mar 26, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Roadiz.
Media articles that mention a CVE ID that affects a product developed by Roadiz — matched by CVE ID, not by vendor name.