gitroom records
7 published records for vendor gitroom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 57.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-42298Proof of concept | Postiz: Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.devgitroom · postiz · CWE-94 | Critical9.8 | — | 0.8% | May 8, 2026 |
36Monitor | CVE-2026-42556No exploit | Postiz stored XSS in public preview pagegitroom · postiz · CWE-79 | Critical9.0 | — | 0.4% | May 8, 2026 |
36Monitor | CVE-2026-40487Proof of concept | Postiz Has Unrestricted File Upload via MIME Type Spoofing that Leads to Stored XSSgitroom · postiz · CWE-79 | Critical9.0 | — | 0.3% | Apr 17, 2026 |
34Monitor | CVE-2026-34577No exploit | Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Checkgitroom · postiz · CWE-918 | High8.6 | — | 0.5% | Apr 2, 2026 |
33Monitor | CVE-2026-34576No exploit | Postiz: SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadatagitroom · postiz · CWE-918 | High8.3 | — | 0.4% | Apr 2, 2026 |
32Monitor | CVE-2026-40168No exploit | Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/streamgitroom · postiz · CWE-918 | High8.2 | — | 0.5% | Apr 10, 2026 |
21Monitor | CVE-2026-34590No exploit | Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validationgitroom · postiz · CWE-918 | Medium5.4 | — | 0.3% | Apr 2, 2026 |
- CVE-2026-4229839Monitor
Postiz: Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev
CriticalCVSS 9.8Proof of conceptEPSS 1%gitroom · postizMay 8, 2026
- CVE-2026-4255636Monitor
Postiz stored XSS in public preview page
CriticalCVSS 9.0No exploitEPSS 0%gitroom · postizMay 8, 2026
- CVE-2026-4048736Monitor
Postiz Has Unrestricted File Upload via MIME Type Spoofing that Leads to Stored XSS
CriticalCVSS 9.0Proof of conceptEPSS 0%gitroom · postizApr 17, 2026
- CVE-2026-3457734Monitor
Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check
HighCVSS 8.6No exploitEPSS 1%gitroom · postizApr 2, 2026
- CVE-2026-3457633Monitor
Postiz: SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata
HighCVSS 8.3No exploitEPSS 0%gitroom · postizApr 2, 2026
- CVE-2026-4016832Monitor
Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream
HighCVSS 8.2No exploitEPSS 1%gitroom · postizApr 10, 2026
- CVE-2026-3459021Monitor
Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validation
MediumCVSS 5.4No exploitEPSS 0%gitroom · postizApr 2, 2026