LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-40487

CVE-2026-40487 - Vulnerability Analysis

HighCVSS: 8.9

Last Updated: April 18, 2026

Postiz - Stored XSS

Published: April 18, 2026Updated: April 18, 2026PoC AvailableRemote Exploitable

Overview

Postiz < 2.21.6 contains a stored XSS caused by file upload validation bypass via spoofed Content-Type header, letting authenticated users upload executable files leading to account takeover, exploit requires authentication.

Severity & Score

Severity: High
CVSS Score: 8.9
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Authenticated attackers can execute stored scripts, leading to account takeover and full compromise of other users.

Mitigation

Update to version 2.21.6 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 18, 2026

🟠 CVE-2026-40487 - High (8.9) Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type` header.... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-40487/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 18, 2026

🟠 CVE-2026-40487 - High (8.9) Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type` header.... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-40487/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-40487
Severity
High
CVSS Score
8.9
Type
stored_xss
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-79

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L

EPSS Score

0.0%Probability of exploitation in the next 30 days