Tag
high
advisory
Postiz SSRF Vulnerability (CVE-2026-40168)
2 rules 1 CVEPostiz, an AI social media scheduling tool, is vulnerable to Server-Side Request Forgery (SSRF) in versions prior to 2.21.5, allowing attackers to access internal resources.
ssrf
cve-2026-40168
postiz
2r
1c
high
advisory
Postiz File Upload Vulnerability Leads to Stored XSS (CVE-2026-40487)
2 rules 5 TTPs 1 CVEAn authenticated file upload validation bypass in Postiz prior to version 2.21.6 allows attackers to upload arbitrary HTML, SVG, or other executable file types by spoofing the `Content-Type` header, resulting in stored XSS and potential account takeover.
Postiz
xss
file-upload
vulnerability
cve-2026-40487
2r
5t
1c