CVEs we hold for Post
Records whose assigning authority named Post as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9577Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod ParameterUnknown Post Status Notifier Lite
CVE-2026-9358postcss-selector-parser AST Serialization container.js toString recursionn/a postcss-selector-parser
CVE-2026-90775PostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated Rule WeightPostGIS address_standardizer
CVE-2026-73646PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosurepostcss
CVE-2026-73514PostGIS address_standardizer Out-of-Bounds Write via standardize_address()PostGIS address_standardizer
CVE-2026-69153PostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMappingURL reads arbitrary .map files when `from`…postcss
CVE-2026-6801Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' Parameterpostmagthemes Context Blog
CVE-2026-6575PostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats arrayn/a PostgreSQL
CVE-2026-6479PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursionn/a PostgreSQL
CVE-2026-6477PostgreSQL libpq lo_* functions let server superuser overwrite client stack memoryn/a PostgreSQL
CVE-2026-6476PostgreSQL pg_createsubscriber allows SQL injection via subscription namen/a PostgreSQL
CVE-2026-6475PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choicen/a PostgreSQL
CVE-2026-6464PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commandsn/a PostgreSQL
CVE-2026-56049WordPress Post Snippets plugin <= 4.0.19 - Remote Code Execution (RCE) vulnerabilityPost Snippets
CVE-2026-45623PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentspostcss
CVE-2026-2007PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memoryn/a PostgreSQL
CVE-2026-2006PostgreSQL missing validation of multibyte character length executes arbitrary coden/a PostgreSQL
CVE-2026-2004PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary coden/a PostgreSQL
CVE-2026-18408PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql clientn/a PostgreSQL
CVE-2026-16260Post Grid, Slider & Carousel Ultimate < 1.8.1 - Contributor+ Stored XSS via Header Title FieldUnknown Post Grid, Slider & Carousel Ultimate
CVE-2026-16239PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary coden/a PostgreSQL
CVE-2026-16238PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary coden/a PostgreSQL
CVE-2026-15742PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparoundn/a PostgreSQL
CVE-2026-14681PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSLn/a PostgreSQL
CVE-2026-14679PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memoryn/a PostgreSQL
CVE-2026-14677PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparoundn/a PostgreSQL
CVE-2026-14676PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary coden/a PostgreSQL
CVE-2026-14672PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oraclen/a PostgreSQL
CVE-2026-14670PostgreSQL plperl tied object heap buffer overflow executes arbitrary coden/a PostgreSQL
CVE-2026-14668PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary readn/a PostgreSQL
CVE-2026-14663PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartextn/a PostgreSQL
CVE-2026-14662PostgreSQL tsvector and tsquery undersize allocations, via integer wraparoundn/a PostgreSQL
CVE-2026-10749Post Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaDataUnknown Post Duplicator
CVE-2025-8715PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target servern/a PostgreSQL
CVE-2025-8714PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql clientn/a PostgreSQL
CVE-2025-8713PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child tablen/a PostgreSQL
CVE-2025-4567Post Slider and Carousel with Widget < 3.2.10 - Admin+ Stored XSSUnknown Post Slider and Post Carousel with Post Vertical…
CVE-2025-4207PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validationn/a PostgreSQL
CVE-2025-1522PostHog database_schema Server-Side Request Forgery Information Disclosure VulnerabilityPostHog
CVE-2025-1521PostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure VulnerabilityPostHog
CVE-2025-1520PostHog ClickHouse Table Functions SQL Injection Remote Code Execution VulnerabilityPostHog
CVE-2025-12074Context Blog <= 1.2.5 - Unauthenticated Private Post Disclosurepostmagthemes Context Blog
CVE-2025-1094PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validationn/a PostgreSQL
CVE-2024-9710PostHog database_schema Server-Side Request Forgery Information Disclosure VulnerabilityPostHog
CVE-2024-9645Post Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSSUnknown Post Grid, Posts Slider, Posts Carousel, Post…
CVE-2024-56005WordPress Posti Shipping Plugin <= 3.10.3 - CSRF to Settings Change vulnerabilityPosti Shipping
CVE-2024-50512WordPress Posti Shipping plugin <= 3.10.2 - Full Path Disclosure (FPD) vulnerabilityPosti Shipping
CVE-2024-4305PostX < 4.1.0 - Contributor+ Stored XSSUnknown Post Grid Gutenberg Blocks and WordPress Blog Plugin
CVE-2024-3239PostX < 4.0.2 - Contributor+ Stored XSSUnknown Post Grid Gutenberg Blocks and WordPress Blog Plugin
CVE-2024-29128WordPress POST SMTP Mailer plugin <= 2.8.6 - Reflected Cross Site Scripting (XSS) vulnerabilityPOST SMTP
CVE-2024-12471Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator <= 1.3.1 - Missing…postsaint Post Saint: ChatGPT, GPT4, DALL-E, Stable…
CVE-2024-11815Pósturinn\'s Shipping with WooCommerce <= 1.3.1 - Reflected Cross-Site Scriptingposturinn Pósturinn\'s Shipping with WooCommerce
CVE-2024-10976PostgreSQL row security below e.g. subqueries disregards user ID changesn/a PostgreSQL
CVE-2024-0985PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQLn/a PostgreSQL
CVE-2024-0881Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts AccessUnknown Post Grid, Form Maker, Popup Maker, WooCommerce…
CVE-2023-5958POST SMTP Mailer < 2.7.1 - Unauthenticated Cross-site ScriptingUnknown POST SMTP Mailer
CVE-2023-52233WordPress POST SMTP Mailer plugin <= 2.8.6 - Broken Access Control on API vulnerabilityPost SMTP Mailer/Email Log
CVE-2023-52195WordPress Posts to Page Plugin <= 1.7 is vulnerable to Cross Site Scripting (XSS)Posts to Page Kerry James
CVE-2023-3992PostX - Gutenberg Post Grid Blocks < 3.0.6 - Reflected Cross-Site ScriptingUnknown PostX
CVE-2023-25459WordPress Post Snippets Plugin <= 4.0.2 is vulnerable to Cross Site Scripting (XSS)Postsnippets Post Snippets
CVE-2023-0526Post Shortcode <= 2.0.9 - Contributor+ Stored Cross-Site ScriptingUnknown Post Shortcode
CVE-2023-0097Post Grid, Post Carousel, & List Category Posts < 2.4.19 - Contributor+ Stored XSSUnknown Post Grid, Post Carousel, & List Category Posts
CVE-2022-4761Post Views Count <= 3.0.2 - Contributor+ Stored XSS in ShortcodeUnknown Post Views Count (Support caching plugins!)
CVE-2022-4749Posts List Designer by Category < 3.2 - Contributor+ Stored XSS via ShortcodeUnknown Posts List Designer by Category
CVE-2022-4747Post Category Image With Grid and Slider < 1.4.8 - Contributor+ Stored XSS via ShortcodeUnknown Post Category Image With Grid and Slider
CVE-2022-3393Post to CSV by BestWebSoft <= 1.4.0 - Author+ CSV InjectionUnknown Post to CSV by BestWebSoft
CVE-2022-2351Post SMTP < 2.1.4 - Admin+ Stored Cross-Site ScriptingUnknown Post SMTP Mailer/Email Log
CVE-2022-1540PostmagThemes Demo <= 1.0.7 - Admin+ Arbitrary File UploadUnknown PostmagThemes Demo Import
CVE-2022-1266Post Grid, Slider & Carousel Ultimate < 1.5.0 - Admin+ Stored XSSUnknown Post Grid, Slider & Carousel Ultimate
CVE-2022-0645Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in posthog/posthogposthog/posthog
CVE-2021-24783Post Expirator < 2.6.0 - Contributor+ Arbitrary Post Schedule DeletionUnknown Post Expirator: Automatically Unpublish WordPress…
CVE-2021-24661PostX Gutenberg Blocks Saved Templates Addon < 2.4.10 - Private Content DisclosureUnknown PostX – Gutenberg Blocks for Post Grid
CVE-2021-24660PostX Gutenberg Blocks Saved Templates Addon < 2.4.10 - Contributor+ Stored Cross-Site ScriptingUnknown PostX – Gutenberg Blocks for Post Grid
CVE-2021-24659PostX Gutenberg Blocks for Post Grid < 2.4.10 - Contributor+ Stored Cross-Site ScriptingUnknown PostX – Gutenberg Blocks for Post Grid
CVE-2021-24652PostX Gutenberg Blocks for Post Grid < 2.4.10 - Missing Access ControlsUnknown PostX – Gutenberg Blocks for Post Grid
CVE-2012-4687Post Oak Bluetooth Traffic Systems Insufficient EntropyPost Oak Traffic Systems AWAM Bluetooth Reader Traffic…
186 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.