GitroomHQ postiz-app

2 known vulnerabilities in GitroomHQ postiz-app, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-94456 CVSS 9.1 critical Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is…
  • CVE-2026-94455 CVSS 7.1 high An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication…