GitroomHQ has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 8.1 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Weakness classes
Products
- postiz-app 2
2
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
GitroomHQ vulnerabilities
CVEs affecting GitroomHQ, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-94456Critical· 9.1Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source
Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE ver…
▾ MidnightGitroomHQ · postiz-appvia NVD
CVE-2026-94455High· 7.1An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session
An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only to an explicit list of controllers, and the enterprise controller is not on th…
▾ TwilightGitroomHQ · postiz-appvia NVD