The record
Every number on this site, and where it came from
Advisory counts, CVE assignments, commits and ranks, each fetched from the system that owns it and stamped with the time it was read.
Checked 15 minutes ago, from 7 sources.
Refreshed every half hour. Nothing here is cached longer than that.
How this works
Every figure quoted on this site is fetched from the system that owns it, on a half-hourly timer, and stored with the URL it came from. Nothing below is typed in by hand, and nothing is counted by this site about itself.
That is a deliberate correction rather than a flourish. Until August 2026 these pages said 48 published advisories and 13 CVEs, in five places at once, because the figures were prose and prose does not update itself. The public record said 33 and 15. A claim a reader can check and find wrong is worth less than no claim at all, so the numbers moved here and the prose now quotes them.
Where each one comes from
The Postiz records come from the GCVE dump for Numbering Authority 125, at the endpoint the GCVE registry itself lists for that authority. Each entry is a full CVE Record Format 5.1 document, so severity, weakness class and CVE assignment are read off the record rather than off a page describing it. Where a record carries both a CVSS 3.1 and a 4.0 vector, the 4.0 one is counted, on the grounds that it is the later opinion.
The totals across both programmes come from the advisory listing on gadvisory.org, counted from the sitemap that platform publishes for machines.
The programme identifiers are checked against the registries rather than quoted from memory. Postiz is CNA-2026-0055, one of 548 CVE Numbering Authorities, with MITRE Corporation as its Top-Level Root. It is also GCVE Numbering Authority 125, one of 45 in that registry.
The contribution figures come from the GitHub contributor graph for each repository the projects page links to. The list is not maintained here: adding a project with a repository URL starts its counters on the next run.
What the conformance line means
GCVE publishes a set of best current practice documents, and BCP-06 is the one covering how a numbering authority should govern itself. GNA 125 publishes a machine-readable self-assessment against it, at a fixed URL, stating the disclosure model, whether allocation is automated, and how long a report waits for its first review. The answer to that last one is 7 days and it is published rather than promised in an email.
BCP-07 covers known-exploited vulnerabilities. GNA 125 publishes that feed too. It currently has 0 entries, which is the good answer.
When a source fails
A source that does not answer leaves its figures exactly as they were. It never blanks them and never writes a zero, because a zero is what a broken parse looks like and a stale number is easier to notice than a confident wrong one. The status line at the top of this page says how many sources answered on the last run, and the page says so plainly when the whole thing has gone stale.
The public record
Every advisory either programme has published, counted from the listings themselves.
advisories_total
advisories_postiz
advisories_gs
cves_total
Severity, Postiz programme
Scored from the CVSS vector on each record, taking the highest version present.
postiz_critical
postiz_high
postiz_medium
postiz_low
Weakness classes
CWE identifiers as recorded, not inferred from the description.
postiz_cwe_classes
postiz_ssrf
postiz_top_cwe
postiz_reporters
Programme identifiers
Registry entries, checked against the registries rather than quoted from memory.
cna_id
cna_root
cna_total
gna_id
gna_vendor
gna_total
gna_updated
bcp_version
conformance_at
review_sla_days
kev_count
Dates
Read off the records rather than remembered, which is the whole argument for this page.
postiz_first
postiz_latest
Upstream
The contribution side of the same codebase the advisories are written against.
commits_total
repos_tracked
repos_lead
postiz_commits
postiz_rank
postiz_contributors
postiz_stars
repos_public
repos_own
stars_tracked
stars_accounts
Repositories
Every repository this site points at
Read from the GitHub contributor graph for each one. The list is whatever the projects page links to, so it grows when a project does rather than when someone remembers to edit it.
Checking one of these
Every source above is public and none of it is mine to edit after the fact. If a number here disagrees with the system it cites, the system is right and I would like to know.