← WordPress Vulnerabilities
WordPress security by component

graphene

graphene is a WordPress theme with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 03, 2026; the highest published CVSS base score is 6.5.

Theme slug: graphene

CVE-2026-81281: Graphene subscribers can store script

Graphene through 2.9.4 allows a Subscriber to supply script-capable content that is rendered without adequate neutralization. A victim who interacts with the affected theme output can execute script in the site's origin.

PublishedSep 03, 2026
Known safe version2.9.6
Published vulnerabilities for graphene
Safe version
Sep 03, 2026 CVE-2026-81281
Graphene subscribers can store script
Graphene through 2.9.4 allows a Subscriber to supply script-capable content that is rendered without adequate neutralization. A victim who interacts with the affected theme output can execute script in the site's origin.
2.9.6
CVE6.5
NVDPending
Apr 09, 2024 CVE-2024-1984
Graphene: A security weakness
Graphene is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending