vciy

CVEs we hold for Post

Records whose assigning authority named Post as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9577Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod ParameterUnknown Post Status Notifier Lite
CVE-2026-9358postcss-selector-parser AST Serialization container.js toString recursionn/a postcss-selector-parser
CVE-2026-90775PostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated Rule WeightPostGIS address_standardizer
CVE-2026-73646PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosurepostcss
CVE-2026-73515PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf BufferPostGIS
CVE-2026-73514PostGIS address_standardizer Out-of-Bounds Write via standardize_address()PostGIS address_standardizer
CVE-2026-69153PostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMappingURL reads arbitrary .map files when `from`…postcss
CVE-2026-6801Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' Parameterpostmagthemes Context Blog
CVE-2026-6638PostgreSQL REFRESH PUBLICATION allows SQL injection via table namen/a PostgreSQL
CVE-2026-6637PostgreSQL refint allows stack buffer overflow and SQL injectionn/a PostgreSQL
CVE-2026-6575PostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats arrayn/a PostgreSQL
CVE-2026-6479PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursionn/a PostgreSQL
CVE-2026-6478PostgreSQL discloses MD5-hashed passwords via covert timing channeln/a PostgreSQL
CVE-2026-6477PostgreSQL libpq lo_* functions let server superuser overwrite client stack memoryn/a PostgreSQL
CVE-2026-6476PostgreSQL pg_createsubscriber allows SQL injection via subscription namen/a PostgreSQL
CVE-2026-6475PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choicen/a PostgreSQL
CVE-2026-6474PostgreSQL timeofday() can disclose portions of server memoryn/a PostgreSQL
CVE-2026-6473PostgreSQL server undersizes allocations, via integer wraparoundn/a PostgreSQL
CVE-2026-6472PostgreSQL CREATE TYPE does not check multirange schema CREATE privilegen/a PostgreSQL
CVE-2026-6471PostgreSQL logical decoding can dlopen arbitrary filen/a PostgreSQL
CVE-2026-6470PostgreSQL fails to check type USAGE privilegen/a PostgreSQL
CVE-2026-6469PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownershipn/a PostgreSQL
CVE-2026-6464PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commandsn/a PostgreSQL
CVE-2026-56049WordPress Post Snippets plugin <= 4.0.19 - Remote Code Execution (RCE) vulnerabilityPost Snippets
CVE-2026-45623PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS commentspostcss
CVE-2026-44742no title heldPostorius
CVE-2026-43964no title heldPostfix
CVE-2026-41305PostCSS has XSS via Unescaped </style> in its CSS Stringify Outputpostcss
CVE-2026-25529Postal has HTML injection / XSS in message viewpostalserver postal
CVE-2026-2007PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memoryn/a PostgreSQL
CVE-2026-2006PostgreSQL missing validation of multibyte character length executes arbitrary coden/a PostgreSQL
CVE-2026-2005PostgreSQL pgcrypto heap buffer overflow executes arbitrary coden/a PostgreSQL
CVE-2026-2004PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary coden/a PostgreSQL
CVE-2026-2003PostgreSQL oidvector discloses a few bytes of memoryn/a PostgreSQL
CVE-2026-19385PostgreSQL pg_dump heap buffer overflow executes arbitrary coden/a PostgreSQL
CVE-2026-18408PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql clientn/a PostgreSQL
CVE-2026-18024PostgreSQL ascii() function reads past end of buffern/a PostgreSQL
CVE-2026-16260Post Grid, Slider & Carousel Ultimate < 1.8.1 - Contributor+ Stored XSS via Header Title FieldUnknown Post Grid, Slider & Carousel Ultimate
CVE-2026-16241PostgreSQL ECPG integer underflow can crash the clientn/a PostgreSQL
CVE-2026-16239PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary coden/a PostgreSQL
CVE-2026-16238PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary coden/a PostgreSQL
CVE-2026-15742PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparoundn/a PostgreSQL
CVE-2026-15741PostgreSQL expression deparse allows SQL injection via EXTRACT argumentn/a PostgreSQL
CVE-2026-14681PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSLn/a PostgreSQL
CVE-2026-14680PostgreSQL type confusion via "internal" argumentsn/a PostgreSQL
CVE-2026-14679PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memoryn/a PostgreSQL
CVE-2026-14678PostgreSQL pg_trgm picksplit reads past end of buffern/a PostgreSQL
CVE-2026-14677PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparoundn/a PostgreSQL
CVE-2026-14676PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary coden/a PostgreSQL
CVE-2026-14673PostgreSQL amcheck does not clear untrusted search pathn/a PostgreSQL
CVE-2026-14672PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oraclen/a PostgreSQL
CVE-2026-14671PostgreSQL refint plan cache type confusion executes arbitrary coden/a PostgreSQL
CVE-2026-14670PostgreSQL plperl tied object heap buffer overflow executes arbitrary coden/a PostgreSQL
CVE-2026-14669PostgreSQL to_char heap buffer overflow executes arbitrary coden/a PostgreSQL
CVE-2026-14668PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary readn/a PostgreSQL
CVE-2026-14666PostgreSQL row security caching disregards role modificationsn/a PostgreSQL
CVE-2026-14664PostgreSQL regexp heap buffer overflow executes arbitrary coden/a PostgreSQL
CVE-2026-14663PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartextn/a PostgreSQL
CVE-2026-14662PostgreSQL tsvector and tsquery undersize allocations, via integer wraparoundn/a PostgreSQL
CVE-2026-10749Post Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaDataUnknown Post Duplicator
CVE-2025-8715PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target servern/a PostgreSQL
CVE-2025-8714PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql clientn/a PostgreSQL
CVE-2025-8713PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child tablen/a PostgreSQL
CVE-2025-5963TCC Bypass via Dylib Injection in PostboxPostbox
CVE-2025-4567Post Slider and Carousel with Widget < 3.2.10 - Admin+ Stored XSSUnknown Post Slider and Post Carousel with Post Vertical…
CVE-2025-4207PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validationn/a PostgreSQL
CVE-2025-15491Post Slides <= 1.0.1 - Contributor+ Local File InclusionUnknown Post Slides
CVE-2025-1522PostHog database_schema Server-Side Request Forgery Information Disclosure VulnerabilityPostHog
CVE-2025-1521PostHog slack_incoming_webhook Server-Side Request Forgery Information Disclosure VulnerabilityPostHog
CVE-2025-1520PostHog ClickHouse Table Functions SQL Injection Remote Code Execution VulnerabilityPostHog
CVE-2025-15095postmanlabs httpbin core.py cross site scriptingpostmanlabs httpbin
CVE-2025-12818PostgreSQL libpq undersizes allocations, via integer wraparoundn/a PostgreSQL
CVE-2025-12817PostgreSQL CREATE STATISTICS does not check for schema CREATE privilegen/a PostgreSQL
CVE-2025-12074Context Blog <= 1.2.5 - Unauthenticated Private Post Disclosurepostmagthemes Context Blog
CVE-2025-1094PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validationn/a PostgreSQL
CVE-2025-0733Postman profapi.dll untrusted search pathn/a Postman
CVE-2024-9710PostHog database_schema Server-Side Request Forgery Information Disclosure VulnerabilityPostHog
CVE-2024-9689Post From Frontend <= 1.0.0 - Post Deletion via CSRFUnknown Post From Frontend
CVE-2024-9645Post Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSSUnknown Post Grid, Posts Slider, Posts Carousel, Post…
CVE-2024-8093Posts reminder <= 0.20 - Settings Update via CSRFUnknown Posts reminder
CVE-2024-7348PostgreSQL relation replacement during pg_dump executes arbitrary SQLn/a PostgreSQL
CVE-2024-56005WordPress Posti Shipping Plugin <= 3.10.3 - CSRF to Settings Change vulnerabilityPosti Shipping
CVE-2024-5200Postie < 1.9.71 - Admin+ Stored XSSUnknown Postie
CVE-2024-50512WordPress Posti Shipping plugin <= 3.10.2 - Full Path Disclosure (FPD) vulnerabilityPosti Shipping
CVE-2024-4317PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checksn/a PostgreSQL
CVE-2024-4305PostX < 4.1.0 - Contributor+ Stored XSSUnknown Post Grid Gutenberg Blocks and WordPress Blog Plugin
CVE-2024-3239PostX < 4.0.2 - Contributor+ Stored XSSUnknown Post Grid Gutenberg Blocks and WordPress Blog Plugin
CVE-2024-29128WordPress POST SMTP Mailer plugin <= 2.8.6 - Reflected Cross Site Scripting (XSS) vulnerabilityPOST SMTP
CVE-2024-27938SMTP Smuggling in Postalpostalserver postal
CVE-2024-13634Post Sync <= 1.1 - Reflected XSSUnknown Post Sync
CVE-2024-13571Post Timeline < 2.3.10 - Reflected XSSUnknown Post Timeline
CVE-2024-12471Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator <= 1.3.1 - Missing…postsaint Post Saint: ChatGPT, GPT4, DALL-E, Stable…
CVE-2024-11815Pósturinn\'s Shipping with WooCommerce <= 1.3.1 - Reflected Cross-Site Scriptingposturinn Pósturinn\'s Shipping with WooCommerce
CVE-2024-10979PostgreSQL PL/Perl environment variable changes execute arbitrary coden/a PostgreSQL
CVE-2024-10978PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user IDn/a PostgreSQL
CVE-2024-10977PostgreSQL libpq retains an error message from man-in-the-middlen/a PostgreSQL
CVE-2024-10976PostgreSQL row security below e.g. subqueries disregards user ID changesn/a PostgreSQL
CVE-2024-10832Posti Shipping <= 3.10.3 - Reflected Cross-Site Scriptingpostioy Posti Shipping
CVE-2024-10815PostLists <= 2.0.2 - Reflected XSSUnknown PostLists
CVE-2024-0985PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQLn/a PostgreSQL
CVE-2024-0881Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts AccessUnknown Post Grid, Form Maker, Popup Maker, WooCommerce…
CVE-2023-7081SQLi in PosTahsil's Online Payment SystemPOSTAHSİL Online Payment System
CVE-2023-6621Post SMTP < 2.8.7 - Reflected Cross-Site ScriptingUnknown POST SMTP
CVE-2023-6620Post SMTP < 2.8.7 - Admin+ SQL InjectionUnknown POST SMTP Mailer
CVE-2023-5958POST SMTP Mailer < 2.7.1 - Unauthenticated Cross-site ScriptingUnknown POST SMTP Mailer
CVE-2023-52233WordPress POST SMTP Mailer plugin <= 2.8.6 - Broken Access Control on API vulnerabilityPost SMTP Mailer/Email Log
CVE-2023-52195WordPress Posts to Page Plugin <= 1.7 is vulnerable to Cross Site Scripting (XSS)Posts to Page Kerry James
CVE-2023-46746Authenticated PostHog users vulnerable to SSRFposthog
CVE-2023-4284Post Timeline < 2.2.6 - Reflected XSSUnknown Post Timeline
CVE-2023-3992PostX - Gutenberg Post Grid Blocks < 3.0.6 - Reflected Cross-Site ScriptingUnknown PostX
CVE-2023-32325Cross-site scripting in PostHog-jsposthog-js
CVE-2023-3179POST SMTP Mailer < 2.5.7 - Account Takeover via CSRFUnknown POST SMTP Mailer
CVE-2023-3178POST SMTP Mailer < 2.5.7 - Arbitrary Log Deletion via CSRFUnknown POST SMTP Mailer
CVE-2023-25459WordPress Post Snippets Plugin <= 4.0.2 is vulnerable to Cross Site Scripting (XSS)Postsnippets Post Snippets
CVE-2023-2455no title heldn/a postgresql
CVE-2023-2454no title heldn/a postgresql
CVE-2023-0526Post Shortcode <= 2.0.9 - Contributor+ Stored Cross-Site ScriptingUnknown Post Shortcode
CVE-2023-0097Post Grid, Post Carousel, & List Category Posts < 2.4.19 - Contributor+ Stored XSSUnknown Post Grid, Post Carousel, & List Category Posts
CVE-2022-4761Post Views Count <= 3.0.2 - Contributor+ Stored XSS in ShortcodeUnknown Post Views Count (Support caching plugins!)
CVE-2022-4749Posts List Designer by Category < 3.2 - Contributor+ Stored XSS via ShortcodeUnknown Posts List Designer by Category
CVE-2022-4747Post Category Image With Grid and Slider < 1.4.8 - Contributor+ Stored XSS via ShortcodeUnknown Post Category Image With Grid and Slider
CVE-2022-4325Post Status Notifier Lite < 1.10.1 - Reflected XSSUnknown Post Status Notifier Lite
CVE-2022-41862no title heldn/a postgresql
CVE-2022-3393Post to CSV by BestWebSoft <= 1.4.0 - Author+ CSV InjectionUnknown Post to CSV by BestWebSoft
CVE-2022-2625no title heldn/a postgresql
CVE-2022-2352Post SMTP < 2.1.7 - Admin+ Blind SSRFUnknown Post SMTP Mailer/Email Log
CVE-2022-2351Post SMTP < 2.1.4 - Admin+ Stored Cross-Site ScriptingUnknown Post SMTP Mailer/Email Log
CVE-2022-1781postTabs <= 2.10.6 - Arbitrary Settings Update via CSRF to Stored XSSUnknown postTabs
CVE-2022-1552no title heldn/a postgresql
CVE-2022-1540PostmagThemes Demo <= 1.0.7 - Admin+ Arbitrary File UploadUnknown PostmagThemes Demo Import
CVE-2022-1266Post Grid, Slider & Carousel Ultimate < 1.5.0 - Admin+ Stored XSSUnknown Post Grid, Slider & Carousel Ultimate
CVE-2022-0748Arbitrary Code Executionn/a post-loader
CVE-2022-0645Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in posthog/posthogposthog/posthog
CVE-2022-0447Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_typesUnknown Post Grid
CVE-2021-38326Post Title Counter <= 1.1 Reflected Cross-Site ScriptingPost Title Counter
CVE-2021-3677no title heldn/a postgresql
CVE-2021-3393no title heldn/a postgresql
CVE-2021-32029no title heldn/a postgresql
CVE-2021-32028no title heldn/a postgresql
CVE-2021-32027no title heldn/a postgresql
CVE-2021-25010Post Snippets < 3.1.4 - CSRF to Stored Cross-Site ScriptingUnknown Post Snippets
CVE-2021-24986Post Grid < 2.1.16 - Reflected Cross-Site Scripting via keywordUnknown Post Grid
CVE-2021-24783Post Expirator < 2.6.0 - Contributor+ Arbitrary Post Schedule DeletionUnknown Post Expirator: Automatically Unpublish WordPress…
CVE-2021-24661PostX Gutenberg Blocks Saved Templates Addon < 2.4.10 - Private Content DisclosureUnknown PostX – Gutenberg Blocks for Post Grid
CVE-2021-24660PostX Gutenberg Blocks Saved Templates Addon < 2.4.10 - Contributor+ Stored Cross-Site ScriptingUnknown PostX – Gutenberg Blocks for Post Grid
CVE-2021-24659PostX Gutenberg Blocks for Post Grid < 2.4.10 - Contributor+ Stored Cross-Site ScriptingUnknown PostX – Gutenberg Blocks for Post Grid
CVE-2021-24652PostX Gutenberg Blocks for Post Grid < 2.4.10 - Missing Access ControlsUnknown PostX – Gutenberg Blocks for Post Grid
CVE-2021-24629Post Content XMLRPC <= 1.0 - Admin+ SQL InjectionsUnknown Post Content XMLRPC
CVE-2021-24613Post Views Counter < 1.3.5 - Authenticated Stored XSSUnknown Post Views Counter
CVE-2021-24488Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)Unknown Post Grid
CVE-2021-23382Regular Expression Denial of Service (ReDoS)n/a postcss
CVE-2021-23368Regular Expression Denial of Service (ReDoS)n/a postcss
CVE-2021-23222no title heldn/a postgresql
CVE-2021-23214no title heldn/a postgresql
CVE-2021-20229no title heldn/a PostgreSQL
CVE-2020-25696no title heldn/a PostgreSQL
CVE-2020-25695no title heldn/a postgresql
CVE-2020-25694no title heldn/a postgresql
CVE-2020-14350no title heldn/a PostgreSQL
CVE-2020-14349no title heldn/a PostgreSQL
CVE-2020-10733no title heldn/a PostgreSQL
CVE-2019-3466no title heldn/a postgresql-common (Debian-specific Postgres management…
CVE-2019-10211no title heldpostgresql
CVE-2019-10210no title heldpostgresql
CVE-2019-10209no title heldpostgresql
CVE-2019-10208no title heldpostgresql
CVE-2019-10164no title heldPostgreSQL
CVE-2019-10130no title heldpostgresql
CVE-2019-10129no title heldpostgresql
CVE-2019-10128no title heldn/a postgresql
CVE-2019-10127no title heldn/a postgresql
CVE-2018-10925no title heldpostgresql
CVE-2018-10915no title heldpostgresql
CVE-2017-8806no title heldn/a PostgreSQL-related scripts that are specific to Debian…
CVE-2017-7548no title heldpostgresql
CVE-2017-7547no title heldpostgresql
CVE-2017-7546no title heldpostgresql
CVE-2015-3167no title heldPostgreSQL
CVE-2015-3166no title heldPostgreSQL
CVE-2015-0244no title heldPostgreSQL
CVE-2015-0243no title heldPostgreSQL
CVE-2015-0242no title heldPostgreSQL
CVE-2015-0241no title heldPostgreSQL
CVE-2014-8161no title heldPostgreSQL
CVE-2012-4687Post Oak Bluetooth Traffic Systems Insufficient EntropyPost Oak Traffic Systems AWAM Bluetooth Reader Traffic…
CVE-2012-0812no title heldpostfixadmin

186 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.