PatchSiren

Groundhogg CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Groundhogg CVE published 2026-06-15

CVE-2026-48885

CVE-2026-48885 is a HIGH severity Unauthenticated Cross Site Scripting (XSS) vulnerability in HollerBox versions up to 2.3.10.1. The vulnerability has a CVSS score of 7.1 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-48885).

MEDIUM Groundhogg CVE published 2026-06-15

CVE-2026-40793

CVE-2026-40793 is a medium-severity vulnerability (CVSS Score: 6.5) affecting Groundhogg, a WordPress plugin, prior to version 4.4.1. The vulnerability is classified as a Subscriber Broken Access Control issue. According to the CVE record [resourceLinkAnnotations:cve-org], it was published on 2026-06-15T21:16:51.660Z and last modified on 2026-06-15T21:24:32.790Z. The vulnerability allows an attacker to po [truncated]

HIGH Groundhogg CVE published 2026-06-15

CVE-2026-40727

CVE-2026-40727 is a HIGH-severity vulnerability in Groundhogg, a WordPress plugin, affecting versions up to 4.4. This vulnerability allows a sales representative to delete arbitrary files, potentially leading to significant system compromise.