← WordPress Vulnerabilities
WordPress security by component

Cozy Blocks

Cozy Blocks is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 6.5.

Plugin slug: cozy-addons

CVE-2026-15393: Cozy Blocks contributors can store script in post metadata icons

Cozy Blocks through 2.2.11 fails to escape the postMeta.font.size block attribute when Cozy\Helpers\BlockRender::categorized_post_tabs_render() inserts it into SVG width and height attributes. A Contributor who can author a categorized-post-tabs block can supply crafted attribute content that becomes executable markup when the post is rendered, causing script to run for visitors to the affected page. The CNA record does not identify additional affected blocks. Version 2.2.12 escapes the attribute at each SVG output location.

PublishedJul 28, 2026
Known safe version2.2.12
Safe version
Jul 28, 2026 CVE-2026-15393
Cozy Blocks contributors can store script in post metadata icons
Cozy Blocks through 2.2.11 fails to escape the postMeta.font.size block attribute when Cozy\Helpers\BlockRender::categorized_post_tabs_render() inserts it into SVG width and height attributes. A Contributor who can author a categorized-post-tabs block can supply crafted attribute content that becomes executable markup when the post is rendered, causing script to run for visitors to the affected page. The CNA record does not identify additional affected blocks. Version 2.2.12 escapes the attribute at each SVG output location.
2.2.12
CVE6.4
NVDPending
Jul 24, 2026 CVE-2026-15334
Cozy Blocks icon attributes permit stored XSS
Cozy Blocks through 2.2.11 lets a Contributor store an attacker-controlled icon.view value in the Advanced Categories block. The server-side blocks/advanced-categories/render.php renderer concatenates that value into an icon-wrapper class without sanitizing the class list; related SVG viewBox, stroke and path attributes were also emitted without contextual escaping. The stored payload executes when the affected block is rendered for a visitor.
2.2.12
CVE6.4
NVDPending
Jul 24, 2026 CVE-2026-15333
Cozy Blocks custom-font attributes permit stored XSS
Cozy Blocks through 2.2.11 lets a Contributor store an attacker-controlled cozyCustomFont block attribute. append_cozy_custom_font_data_attributes() inserts that value into inline font-family CSS and a Google Fonts link href while filtering rendered core and Cozy blocks, without first constraining or contextually escaping it. The resulting stored payload executes whenever the affected block is rendered.
2.2.12
CVE6.4
NVDPending
Sep 22, 2025 CVE-2025-59573
Cozy Blocks: Cross-site scripting
Cozy Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.3
NVDPending
May 07, 2025 CVE-2025-47485
Cozy Blocks: A security weakness
Cozy Blocks is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Mar 27, 2025 CVE-2025-30838
Cozy Blocks: Cross-site scripting
Cozy Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Oct 06, 2024 CVE-2024-47355
Cozy Blocks: Cross-site scripting
Cozy Blocks is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending