
CVE-2026-42556 Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in p… https://www.cve.org/CVERecord?id=CVE-2026-42556
Post summary
The CVE reports a stored XSS flaw in Postiz versions 2.21.6 up to before 2.21.7, allowing authenticated users to inject arbitrary HTML into posts; no PoC, exploit, active exploitation, or patch details are provided.
