CVE-2017-6480: Groovel Project Cmsgroovel

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter).

Affected products

Published 2017-03-05. Last modified 2026-06-17.