postiz-app vulnerabilities
CVEs whose affected-version data names the postiz-app package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-94456Critical· 9.1Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source
Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE ver…
▾ MidnightGitroomHQ · postiz-appvia NVD
CVE-2026-94455High· 7.1An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session
An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only to an explicit list of controllers, and the enterprise controller is not on th…
▾ TwilightGitroomHQ · postiz-appvia NVD