VYPR
Medium severity6.1OSV Advisory· Published Jan 13, 2026· Updated Jun 17, 2026

CVE-2023-54341

CVE-2023-54341

Description

Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts via the file parameter in index.php. The application does not sufficiently encode user-controlled inputs, allowing attackers to execute arbitrary JavaScript in victim's browsers by crafting malicious URLs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Range: 0.3, 0.4, 0.5, …
  • cpe:2.3:a:webgrind_project:webgrind:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:webgrind_project:webgrind:*:*:*:*:*:*:*:*range: <=1.1
    • (no CPE)range: <=1.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.