WordPress security by component
graphene
graphene is a WordPress theme with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 03, 2026; the highest published CVSS base score is 6.5.
Theme slug:
grapheneLatest vulnerability
CVE-2026-81281: Graphene subscribers can store script
Graphene through 2.9.4 allows a Subscriber to supply script-capable content that is rendered without adequate neutralization. A victim who interacts with the affected theme output can execute script in the site's origin.
| Safe version |
|
||
|---|---|---|---|
| Sep 03, 2026 |
CVE-2026-81281
Graphene subscribers can store script
Graphene through 2.9.4 allows a Subscriber to supply script-capable content that is rendered without adequate neutralization. A victim who interacts with the affected theme output can execute script in the site's origin.
|
2.9.6 |
CVE6.5
NVDPending
|
| Apr 09, 2024 |
CVE-2024-1984
Graphene: A security weakness
Graphene is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|