Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 18 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitroom
Gitroom postiz |
|
| CPEs | cpe:2.3:a:gitroom:postiz:2.21.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitroom
Gitroom postiz |
Wed, 13 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitroomhq
Gitroomhq postiz-app |
|
| Vendors & Products |
Gitroomhq
Gitroomhq postiz-app |
Fri, 08 May 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request and send the public preview link /p/<postId>?share=true to another user. The preview page renders that stored HTML with dangerouslySetInnerHTML on the main application origin. This issue has been patched in version 2.21.7. | |
| Title | Postiz stored XSS in public preview page | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-13T17:46:47.709Z
Reserved: 2026-04-28T16:56:50.192Z
Link: CVE-2026-42556
Updated: 2026-05-13T17:46:41.543Z
Status : Analyzed
Published: 2026-05-08T23:16:39.373
Modified: 2026-05-18T14:27:09.653
Link: CVE-2026-42556
No data.
OpenCVE Enrichment
Updated: 2026-05-08T23:30:15Z