CVE-2023-54341: Webgrind Project Webgrind
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts via the file parameter in index.php. The application does not sufficiently encode user-controlled inputs, allowing attackers to execute arbitrary JavaScript in victim's browsers by crafting malicious URLs.
Affected products
- Webgrind Project Webgrind: up to and including 1.1
Published 2026-01-13. Last modified 2026-06-17.