The Postiz open-source social media scheduling tool is vulnerable to a critical path traversal issue (CVE-2026-19264) that allows unauthenticated remote attackers to read any file readable by the application process. This vulnerability, with a CVSS score of 9.3, enables attackers to access sensitive data such as JWT signing secrets, database connection strings, and connected provider and billing secrets. [truncated]
CVE-2026-19127 allows remote attackers to bypass payment authorization workflows by exploiting insufficient cryptographic validation or lack of server-side state verification on promotional/lifetime-deal redemption codes. This enables an unauthenticated attacker to forge valid redemption tokens or replay existing single-use codes to activate permanent, tier-highest paid subscriptions without a financial transaction.
CVE-2026-48783 is a medium-severity vulnerability in Postiz, an AI social media scheduling tool. The issue, fixed in version 2.21.8, involves an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side effects to the organization referenced in that token's claims, without verifying the token's intended purpose. The endpoint could not change the persisted subscription [truncated]
CVE-2026-48781 is a critical vulnerability in Postiz, an AI social media scheduling tool. Versions prior to 2.21.8 are affected, allowing attackers to forge a SUPERADMIN session and impersonate arbitrary organizations. This vulnerability, with a CVSS score of 9.9, enables full access to all parts of Postiz, including user data and social media channels. The issue arises from the Skool integration callback [truncated]