CVE-2026-42556
8.9 HIGHPostiz is an AI social media scheduling tool
Published: 2026-05-08 · Last updated: 2026-05-18
Severity and scoring
- CVSS
- 8.9 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
- CWE
- CWE-79
Affected products
| Vendor | Product |
|---|---|
| gitroom | postiz |
Description
Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request and send the public preview link /p/<postId>?share=true to another user. The preview page renders that stored HTML with dangerouslySetInnerHTML on the main application origin. This issue has been patched in version 2.21.7.
Source: NVD
References
Related CVEs
Same vendor
- CVE-2026-42298 — Postiz is an AI social media scheduling tool (10.0 CRITICAL)
Same CWE
- CVE-2026-9125 — The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_ov... (6.4 MEDIUM)
- CVE-2026-42653 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP allows Stored XSS (7.1 HIGH)
- CVE-2026-46489 — SolidInvoice is an open-source invoicing platform (8.1 HIGH)
- CVE-2026-8589 — GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0... (7.3 HIGH)
- CVE-2026-10087 — GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2... (8.7 HIGH)