CVE-2026-15541High· 7.3▾ TwilightA flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
0.3% → 0.5%
A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent can lead to missing authorization. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13813Medium· 5.6A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2
CVE-2024-0829Medium· 4.3The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0
CVE-2026-19350Medium· 6.3A vulnerability has been found in Dolibarr ERP up to 23.0.3
CVE-2026-19345Medium· 6.5A vulnerability was found in code-projects Task Management System 1.0
CVE-2026-16215Medium· 6.5A security flaw has been discovered in geex-arts django-jet up to 1.0.8
CVE-2026-16197Medium· 6.3A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9