VYPR

Grand News

by WordPress

CVEs (2)

  • CVE-2026-42705HigOct 10, 2026
    risk 0.49cvss 7.5epss —

    Unauthenticated Broken Access Control in Grand News <= 3.4 versions.

  • CVE-2026-27353HigMar 5, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand News grandnews allows Reflected XSS.This issue affects Grand News: from n/a through <= 3.4.3.