Skip to content
Noroxi

gitroom records

7 published records for vendor gitroom.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
57.1%
Median publish → KEV
No record has entered KEV

All records

7 records
  • Postiz: Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    gitroom · postizMay 8, 2026

  • Postiz stored XSS in public preview page

    CriticalCVSS 9.0No exploitEPSS 0%

    gitroom · postizMay 8, 2026

  • Postiz Has Unrestricted File Upload via MIME Type Spoofing that Leads to Stored XSS

    CriticalCVSS 9.0Proof of conceptEPSS 0%

    gitroom · postizApr 17, 2026

  • Postiz: Unauthenticated Full-Read SSRF via /public/stream Endpoint with Trivially Bypassable Extension Check

    HighCVSS 8.6No exploitEPSS 1%

    gitroom · postizApr 2, 2026

  • Postiz: SSRF in upload-from-url endpoint allows fetching internal resources and cloud metadata

    HighCVSS 8.3No exploitEPSS 0%

    gitroom · postizApr 2, 2026

  • Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream

    HighCVSS 8.2No exploitEPSS 1%

    gitroom · postizApr 10, 2026

  • Postiz: SSRF via Webhook Creation Endpoint Missing URL Safety Validation

    MediumCVSS 5.4No exploitEPSS 0%

    gitroom · postizApr 2, 2026