Webgrind Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-54341

    Webgrind 1.1 - Reflected Cross-Site Scripting (XSS) via file Parameter

    Last Modified: Mar 05, 2026
    Published: Jan 13, 2026

    CVE-2023-54339

    Webgrind 1.1 - Remote Command Execution (RCE) via dataFile Parameter

    Last Modified: Mar 05, 2026
    Published: Jan 13, 2026

    CVE-2018-12909

    Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the webserver user has access to) via an index.php?op=fileviewer&file= URI. NOTE: the vendor indicates that the product is not intended for a "publicly accessible environment.

    Last Modified: Nov 21, 2024
    Published: Jun 27, 2018

    CVE-2012-1790

    Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php.

    Last Modified: Apr 11, 2025
    Published: Mar 19, 2012
    Items Per Page
    Webgrind_Project Vulnerabilities & Security CVEs | CVE-DB