CVE-2026-40487 | Postiz <= 2.21.5 | Arbitrary File Upload via MIME-Type Spoofing → Stored XSS → Account Takeover | CVSS 8.9 High
security exploit file-upload xss poc vulnerability cve account-takeover stored-xss postiz mime-spoofing cve-2026-40487
-
Updated
Apr 16, 2026 - Python