Nevo David
4 exploits
Active since Apr 2026
Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
CVSS 9.9
Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription
CVSS 4.8
Postiz: TOCTOU DNS rebinding bypasses all SSRF URL validation paths
CVSS 6.5
Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream
CVSS 8.2