CVE-2026-17025Medium· 6.4▾ SunlitThe Graphene theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'Current location' and 'Author profile image URL' Profile Fields in all versions up to, and including, 2.9.4 due to insufficient input sanitization and out…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Graphene theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'Current location' and 'Author profile image URL' Profile Fields in all versions up to, and including, 2.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107819Medium· 5.9MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases
CVE-2026-107890Low· 3.3OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference caused by repeated IPP group tags in job-creation requests
CVE-2026-107889Medium· 5.5A flaw was found in the login theme rendering component of Keycloak
CVE-2026-107888Medium· 5.1OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create refers to a temporary printer that has been automatically deleted
CVE-2026-107886Low· 2.3OpenPrinting CUPS before 2.4.20 contains a double-free in printer-class management
CVE-2026-107885Low· 3.3OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs()