Product
critical
advisory
Critical Path Traversal in Postiz Exploited for Instance Takeover
1 rule 2 TTPs 1 CVEAn unauthenticated path traversal vulnerability (CVE-2026-19264) in Postiz enables remote attackers to read sensitive configuration files, facilitate JWT secret theft, and achieve full instance takeover through forged administrative sessions.
Postiz
path-traversal
instance-takeover
cve-2026-19264
1r
2t
1c
high
advisory
Postiz File Upload Vulnerability Leads to Stored XSS (CVE-2026-40487)
2 rules 5 TTPs 1 CVEAn authenticated file upload validation bypass in Postiz prior to version 2.21.6 allows attackers to upload arbitrary HTML, SVG, or other executable file types by spoofing the `Content-Type` header, resulting in stored XSS and potential account takeover.
Postiz
xss
file-upload
vulnerability
cve-2026-40487
2r
5t
1c