CVE-2026-97070

CozyThemes Cozy Blocks

Published 5 Oct 2026 · updated 5 Oct 2026 · Received

6.9 Medium · CVSS 4.0, patchstack.com

Description

Authorization Bypass Through User-Controlled Key vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: from n/a through 2.2.23.

References