groovel/cmsgroovel prior to 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter).
groovel project cmsgroovel