Ghostwire

CVE-2026-42556: Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who...

HIGH CVSS 8.9 1 PoC

Published: May 8, 2026 | Last Modified: May 8, 2026

Description

Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their own save request and send the public preview link /p/<postId>?share=true to another user. The preview page renders that stored HTML with dangerouslySetInnerHTML on the main application origin. This issue has been patched in version 2.21.7.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Proof-of-Concept Exploits (1)

Security Coverage (1 articles)

References