VendorsWebgrind projectwebgrindall versions
Vulnerabilities

Webgrind project Webgrind

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-54339
Webgrind 1.1 - Remote Command Execution (RCE) via dataFile Parameter
Published 2026-01-13 · Analyzed
9.8EPSS 0.017
CVE-2018-12909
Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the webserver user has access to) via an index.php?op=fileviewer&file= URI. NOTE: the vendor indicates that the product is not intended for a "publicly accessible environment.
Published 2018-06-27 · Modified
7.8EPSS 0.161
CVE-2023-54341
Webgrind 1.1 - Reflected Cross-Site Scripting (XSS) via file Parameter
Published 2026-01-13 · Analyzed
6.1EPSS 0.004
CVE-2012-1790
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php.
Published 2012-03-19 · Modified
5.01 PoCEPSS 0.051