CVE-2023-54341 MEDIUM

CVE-2023-54341: Webgrind 1.1 - Reflected Cross-Site Scripting (XSS) via file Parameter

Vendor Jokkedk
Product Webgrind
Weakness CWE-79 · XSS
Published January 13, 2026
Last update March 5, 2026

CVSS base score

6.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts via the file parameter in index.php. The application does not sufficiently encode user-controlled inputs, allowing attackers to execute arbitrary JavaScript in victim's browsers by crafting malicious URLs.

Key dates

02Disclosure timeline

January 13, 2026 CVE published
March 5, 2026 Record updated

Related vulnerabilities

04Related CVE