PSA-2026-04-ZR1M2026-04-19
7.1 High

Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)

Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader (CWE-918)

Postiz has multiple SSRF vulnerabilities where user-provided URLs are fetched server-side without any IP validation or SSRF protection.