The record

Every number on this site, and where it came from

Advisory counts, CVE assignments, commits and ranks, each fetched from the system that owns it and stamped with the time it was read.

Checked 15 minutes ago, from 7 sources.

Refreshed every half hour. Nothing here is cached longer than that.

How this works

Every figure quoted on this site is fetched from the system that owns it, on a half-hourly timer, and stored with the URL it came from. Nothing below is typed in by hand, and nothing is counted by this site about itself.

That is a deliberate correction rather than a flourish. Until August 2026 these pages said 48 published advisories and 13 CVEs, in five places at once, because the figures were prose and prose does not update itself. The public record said 33 and 15. A claim a reader can check and find wrong is worth less than no claim at all, so the numbers moved here and the prose now quotes them.

Where each one comes from

The Postiz records come from the GCVE dump for Numbering Authority 125, at the endpoint the GCVE registry itself lists for that authority. Each entry is a full CVE Record Format 5.1 document, so severity, weakness class and CVE assignment are read off the record rather than off a page describing it. Where a record carries both a CVSS 3.1 and a 4.0 vector, the 4.0 one is counted, on the grounds that it is the later opinion.

The totals across both programmes come from the advisory listing on gadvisory.org, counted from the sitemap that platform publishes for machines.

The programme identifiers are checked against the registries rather than quoted from memory. Postiz is CNA-2026-0055, one of 548 CVE Numbering Authorities, with MITRE Corporation as its Top-Level Root. It is also GCVE Numbering Authority 125, one of 45 in that registry.

The contribution figures come from the GitHub contributor graph for each repository the projects page links to. The list is not maintained here: adding a project with a repository URL starts its counters on the next run.

What the conformance line means

GCVE publishes a set of best current practice documents, and BCP-06 is the one covering how a numbering authority should govern itself. GNA 125 publishes a machine-readable self-assessment against it, at a fixed URL, stating the disclosure model, whether allocation is automated, and how long a report waits for its first review. The answer to that last one is 7 days and it is published rather than promised in an email.

BCP-07 covers known-exploited vulnerabilities. GNA 125 publishes that feed too. It currently has 0 entries, which is the good answer.

When a source fails

A source that does not answer leaves its figures exactly as they were. It never blanks them and never writes a zero, because a zero is what a broken parse looks like and a stale number is easier to notice than a confident wrong one. The status line at the top of this page says how many sources answered on the last run, and the page says so plainly when the whole thing has gone stale.

The public record

Every advisory either programme has published, counted from the listings themselves.

Advisories on the public record, both programmes advisories_total
33 gadvisory.org sitemap · last changed 23 days ago
Advisories published by the Postiz programme advisories_postiz
17 GCVE GNA 125 dump · last changed 23 days ago
Advisories published under the Gelhaus Solutions prefix advisories_gs
16 gadvisory.org sitemap · last changed 23 days ago
CVE identifiers assigned cves_total
15 GCVE GNA 125 dump · last changed 23 days ago

Severity, Postiz programme

Scored from the CVSS vector on each record, taking the highest version present.

Critical severity postiz_critical
3 CVSS vectors on the records · last changed 23 days ago
High severity postiz_high
7 CVSS vectors on the records · last changed 23 days ago
Medium severity postiz_medium
7 CVSS vectors on the records · last changed 23 days ago
Low severity postiz_low
0 CVSS vectors on the records · last changed 23 days ago

Weakness classes

CWE identifiers as recorded, not inferred from the description.

Distinct CWE classes on the record postiz_cwe_classes
12 CWE identifiers on the records · last changed 23 days ago
Server-side request forgery advisories postiz_ssrf
8 CWE-918 on the records · last changed 23 days ago
Largest weakness cluster postiz_top_cwe
CWE-918 CWE identifiers on the records · last changed 23 days ago
People credited on the records postiz_reporters
15 Credits on the records · last changed 23 days ago

Programme identifiers

Registry entries, checked against the registries rather than quoted from memory.

CNA identifier cna_id
CNA-2026-0055 CVE Program partner list · last changed 23 days ago
Top-Level Root cna_root
MITRE Corporation CVE Program partner list · last changed 23 days ago
CNAs in the CVE Program cna_total
548 CVE Program partner list · last changed 4 days ago
GCVE Numbering Authority gna_id
125 GCVE registry · last changed 23 days ago
CPE vendor name on the registry entry gna_vendor
gitroomhq GCVE registry · last changed 23 days ago
Numbering authorities in the GCVE registry gna_total
45 GCVE registry · last changed 9 days ago
Registry entry last updated gna_updated
2026-09-04 GCVE registry · last changed 9 days ago
Conformance statement version bcp_version
BCP-06-1.0 GNA 125 conformance endpoint · last changed 23 days ago
Conformance statement last updated conformance_at
2026-09-13 GNA 125 conformance endpoint · last changed 14 hours ago
Days to first review, as published review_sla_days
7 GNA 125 conformance endpoint · last changed 23 days ago
Assigned identifiers on the programme's known-exploited feed kev_count
0 GNA 125 BCP-07 feed · last changed 23 days ago

Dates

Read off the records rather than remembered, which is the whole argument for this page.

First advisory published postiz_first
2026-04-19 GCVE GNA 125 dump · last changed 23 days ago
Most recent advisory postiz_latest
2026-08-15 GCVE GNA 125 dump · last changed 23 days ago

Upstream

The contribution side of the same codebase the advisories are written against.

My commits across every repository listed here commits_total
1,201 GitHub commit history, merges included · last changed 4 days ago
Repositories with live figures on this site repos_tracked
5 GitHub · last changed 23 days ago
Of those, where I am the top contributor repos_lead
2 GitHub contributor graphs · last changed 23 days ago
My commits to Postiz postiz_commits
405 GitHub commit history, merges included · last changed 11 days ago
My position on Postiz postiz_rank
2 GitHub contributor graph · last changed 23 days ago
Contributors to Postiz postiz_contributors
70 GitHub contributor graph · last changed 12 days ago
Stars on Postiz postiz_stars
35,753 GitHub · last changed 48 minutes ago
Public repositories across both accounts repos_public
19 GitHub · last changed 6 days ago
Repositories that are mine rather than forks repos_own
6 GitHub · last changed 23 days ago
Stars across those repositories stars_tracked
35,769 GitHub · last changed 48 minutes ago
Stars across both accounts stars_accounts
14 GitHub · last changed 23 days ago

Repositories

Every repository this site points at

Read from the GitHub contributor graph for each one. The list is whatever the projects page links to, so it grows when a project does rather than when someone remembers to edit it.

264 commits Top contributor of 2 · 3 stars · last commit
50 commits Number 2 of 21 · 1 stars · last commit
264 commits Number 2 of 100 · 8 stars · last commit

Checking one of these

Every source above is public and none of it is mine to edit after the fact. If a number here disagrees with the system it cites, the system is right and I would like to know.