CVE-2026-40487 - Postiz <= 2.21.5 - Arbitrary File Upload via MIME-Type Spoofing → Stored XSS → Account Takeover
-
Updated
Apr 22, 2026 - Python
CVE-2026-40487 - Postiz <= 2.21.5 - Arbitrary File Upload via MIME-Type Spoofing → Stored XSS → Account Takeover
Reusable Postiz MCP server for integrations, posts, upload-from-url media, and draft creation
[ARCHIVED — merged into github.com/howardleegeek/growth-os/tree/main/clawmarketing]
Add a description, image, and links to the postiz topic page so that developers can more easily learn about it.
To associate your repository with the postiz topic, visit your repo's landing page and select "manage topics."