Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-94455 is a vulnerability in GitroomHQ's postiz-app affecting versions before 2.4.0. An HTTP endpoint used for provisioning enterprise and reseller organizations lacks proper authentication because the middleware does not protect the enterprise controller routes. The endpoint only verifies a token signature but does not validate token purpose, audience, or expiry, allowing an attacker with a valid user session token to create a high-tier organization with lifetime privileges and obtain its API key. Join the discussion | CVE Database V5 | 09/22/2026, 16:17:00 UTC Added: 09/22/2026, 16:33:28 UTC |
0 CVE-2026-94456 is a critical vulnerability in GitroomHQ's postiz-app where security-sensitive credentials are generated using a non-cryptographically secure pseudorandom number generator (Math.random()). This affects OAuth tokens, client secrets, API keys, and PKCE verifiers. An unauthenticated OAuth dynamic client registration endpoint leaks freshly generated client credentials, allowing attackers to reconstruct the internal PRNG state and predict past and future credentials, compromising user and organization security. Join the discussion | CVE Database V5 | 09/22/2026, 16:11:33 UTC Added: 09/22/2026, 16:33:28 UTC |
0 Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments are collapsed before routing, but URL-encoded separators survive route matching and are decoded only once they reach the handler, restoring the traversal at the filesystem call. An unauthenticated remote attacker can therefore read any file readable by the application process, including the process environment, which exposes the JWT signing secret, the database connection string, and connected provider and billing secrets. Because session tokens are signed with that secret and carry no expiry, this allows forging a non-expiring session as any user, including an administrator, without a password. Join the discussion | CVE Database V5 | 08/07/2026, 14:15:15 UTC Added: 08/07/2026, 14:42:02 UTC |
0 Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads the target subscription identifier from the untrusted request body, allowing a low-privileged account to grant arbitrary organizations lifetime PRO subscriptions without payment. This issue is fixed in version 2.21.8. Join the discussion | CVE Database V5 | 07/15/2026, 16:11:24 UTC Added: 07/15/2026, 16:33:05 UTC |
0 Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's intended purpose. The endpoint, /public/modify-subscription, could not change the persisted subscription tier, but it did execute enforcement-related side effects on the caller's own organization, including adjusting team-member enablement state, disabling integrations exceeding the asserted plan's limits, and resetting the scheduled-post cron when the asserted plan was the free tier. Impact is limited to the attacker's own organization and cannot be redirected at other tenants through this endpoint. This issue has been fixed in version 2.21.8. Join the discussion | CVE Database V5 | 06/16/2026, 21:38:00 UTC Added: 06/16/2026, 22:01:12 UTC |
0 Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user from the database. Any authenticated Postiz user could forge a SUPERADMIN session and impersonate arbitrary organizations. This allowed Full Access to the following: all parts of Postiz, including users registered to the specific instance and the ability to post in the name of the victim's social media channels added to that Postiz instance. This issue has been fixed in version 2.21.8. Join the discussion | CVE Database V5 | 06/16/2026, 21:31:28 UTC Added: 06/16/2026, 22:01:09 UTC |
0 Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request and send the public preview link /p/<postId>?share=true to another user. The preview page renders that stored HTML with dangerouslySetInnerHTML on the main application origin. This issue has been patched in version 2.21.7. Join the discussion | CVE Database V5 | 05/08/2026, 22:28:33 UTC Added: 05/08/2026, 22:51:25 UTC |
Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added in v2.21.4–v2.21.6 share a fundamental TOCTOU (Time-of-Check-Time-of-Use) vulnerability: isSafePublicHttpsUrl() resolves DNS to validate the target IP, but subsequent fetch() calls resolve DNS independently. An attacker controlling a DNS server can exploit this gap via DNS rebinding to redirect requests to internal network addresses. This issue has been patched in version 2.21.7. Join the discussion | CVE Database V5 | 05/08/2026, 22:26:50 UTC Added: 05/08/2026, 22:51:25 UTC |
0 Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type` header. The uploaded files are then served by nginx with a Content-Type derived from their original extension (`text/html`, `image/svg+xml`), enabling Stored Cross-Site Scripting (XSS) in the context of the application's origin. This can lead to session riding, account takeover, and full compromise of other users' accounts. Version 2.21.6 contains a fix. Join the discussion | CVE Database V5 | 04/18/2026, 01:19:06 UTC Added: 04/18/2026, 01:38:08 UTC |
Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application validates the initially supplied URL and blocks direct private/internal hosts, it does not re-validate the final destination after HTTP redirects. As a result, an attacker can supply a public HTTPS URL that passes validation and then redirects the server-side request to an internal resource. Join the discussion | CVE Database V5 | 04/10/2026, 19:20:16 UTC Added: 04/11/2026, 05:17:38 UTC |
Showing 1 to 10 of 14 results