CVE-2026-96680Medium· 4.3▾ SunlitA vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.addListener of the file static/background/index.js of the component External Me…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.addListener of the file static/background/index.js of the component External Message Handler. The manipulation of the argument body.url/paginationConfig/xPathConfig/body.urls/xPaths results in missing authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13813Medium· 5.6A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2
CVE-2024-0829Medium· 4.3The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0
CVE-2026-19350Medium· 6.3A vulnerability has been found in Dolibarr ERP up to 23.0.3
CVE-2026-19345Medium· 6.5A vulnerability was found in code-projects Task Management System 1.0
CVE-2026-16215Medium· 6.5A security flaw has been discovered in geex-arts django-jet up to 1.0.8
CVE-2026-16197Medium· 6.3A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9