{"api_version":"v1","generated_at":"2026-10-08T00:10:00+00:00","product":{"cve_count":13,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-gitroomhq-postiz-app-5af632e0eaeb","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"postiz-app","next_cursor":null,"observations":[{"affected":"postiz-app: < 2.4.0","affected_versions_present":true,"cve_id":"CVE-2026-94455","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-94455","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-22T18:14:13.947Z","patch_url":"","primary_source":"","published":"2026-09-22T16:17:00.413Z"},{"affected":"postiz-app: < 2.4.0","affected_versions_present":true,"cve_id":"CVE-2026-94456","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-94456","fixed":"Run a Postiz release in which security-sensitive identifiers are generated from a cryptographically secure random source rather than from Math.random(). No fixed release is available at the time of writing; this advisory will record the fixed version once one is published.","last_modified":"2026-09-22T18:11:17.502Z","patch_url":"https://github.com/gitroomhq/postiz-app","primary_source":"","published":"2026-09-22T16:11:33.674Z"},{"affected":"< 2.22.1","affected_versions_present":true,"cve_id":"CVE-2026-19264","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-19264","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-24T11:15:08.324Z","patch_url":"","primary_source":"","published":"2026-08-07T14:15:15.123Z"},{"affected":"< 2.21.10","affected_versions_present":true,"cve_id":"CVE-2026-19127","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-19127","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T14:03:32.512Z","patch_url":"","primary_source":"","published":"2026-08-06T17:02:44.054Z"},{"affected":"< 2.21.8","affected_versions_present":true,"cve_id":"CVE-2026-48799","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48799","fixed":"2.21.8.","last_modified":"2026-07-15T18:01:49.289Z","patch_url":"https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-j7rp-5mgj-qgg9","primary_source":"","published":"2026-07-15T16:11:24.967Z"},{"affected":"< 2.21.8","affected_versions_present":true,"cve_id":"CVE-2026-48783","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48783","fixed":"2.21.8.","last_modified":"2026-06-17T12:43:39.751Z","patch_url":"https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-v4wr-4j8g-4hfj","primary_source":"","published":"2026-06-16T21:38:00.674Z"},{"affected":"< 2.21.8","affected_versions_present":true,"cve_id":"CVE-2026-48781","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48781","fixed":"2.21.8.","last_modified":"2026-06-18T14:26:17.633Z","patch_url":"https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-j77w-h625-56q2","primary_source":"","published":"2026-06-16T21:31:28.955Z"},{"affected":">= 2.21.6, < 2.21.7","affected_versions_present":true,"cve_id":"CVE-2026-42556","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42556","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-13T17:46:47.709Z","patch_url":"","primary_source":"","published":"2026-05-08T22:28:33.086Z"},{"affected":">= 2.16.6, < 2.21.7","affected_versions_present":true,"cve_id":"CVE-2026-42346","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42346","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-11T14:35:55.041Z","patch_url":"","primary_source":"","published":"2026-05-08T22:26:50.501Z"},{"affected":"< da448012dd87e94944cbe83a38e7fd023269ec46","affected_versions_present":true,"cve_id":"CVE-2026-42298","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42298","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-11T18:02:03.832Z","patch_url":"","primary_source":"","published":"2026-05-08T22:24:10.249Z"},{"affected":"< 2.21.6","affected_versions_present":true,"cve_id":"CVE-2026-40487","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40487","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-20T15:25:40.893Z","patch_url":"","primary_source":"","published":"2026-04-18T01:19:06.588Z"},{"affected":"< 2.21.5","affected_versions_present":true,"cve_id":"CVE-2026-40168","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40168","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-13T20:55:15.792Z","patch_url":"https://github.com/gitroomhq/postiz-app/commit/30e8b777098157362769226d1b46d83ad616cb06","primary_source":"","published":"2026-04-10T19:20:16.365Z"},{"affected":"< 2.21.4","affected_versions_present":true,"cve_id":"CVE-2026-34590","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34590","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-03T15:49:51.856Z","patch_url":"https://github.com/gitroomhq/postiz-app/commit/5ae4c950db6aa516a31454b7a45b9480bca40a11","primary_source":"","published":"2026-04-02T17:26:58.902Z"},{"affected":"< 2.21.3","affected_versions_present":true,"cve_id":"CVE-2026-34577","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34577","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-03T15:52:56.345Z","patch_url":"https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-mv6h-v3jg-g539","primary_source":"","published":"2026-04-02T17:24:33.725Z"},{"affected":"< 2.21.3","affected_versions_present":true,"cve_id":"CVE-2026-34576","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34576","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-02T18:57:33.241Z","patch_url":"https://github.com/gitroomhq/postiz-app/security/advisories/GHSA-89vp-m2qw-7v34","primary_source":"","published":"2026-04-02T17:23:14.827Z"},{"affected":">= 1.45.1, < 1.62.3","affected_versions_present":true,"cve_id":"CVE-2025-53641","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-53641","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-07-11T17:56:30.605Z","patch_url":"","primary_source":"","published":"2025-07-11T17:28:20.001Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"GitroomHQ"}}
