<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:28:07.301039+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2020:4682</id>
    <title>ALSA-2020:4682 — Moderate: grafana security, bug fix, and enhancement update</title>
    <updated>2026-10-03T17:28:07.418286+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: grafana, AlmaLinux:8: grafana-azure-monitor, AlmaLinux:8: grafana-cloudwatch, AlmaLinux:8: grafana-elasticsearch, AlmaLinux:8: grafana-graphite, AlmaLinux:8: grafana-influxdb, AlmaLinux:8: grafana-loki, AlmaLinux:8: grafana-mssql, AlmaLinux:8: grafana-mysql, AlmaLinux:8: grafana-opentsdb and 3 more</p>
<p>Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp; OpenTSDB.</p>
<p>The following packages have been upgraded to a later upstream version: grafana (6.7.4). (BZ#1807323)</p>
<p>Security Fix(es):</p>
<p>* grafana: XSS vulnerability via a column style on the "Dashboard &gt; Table Panel" screen (CVE-2018-18624)</p>
<p>* grafana: arbitrary file read via MySQL data source (CVE-2019-19499)</p>
<p>* grafana: stored XSS (CVE-2020-11110)</p>
<p>* grafana: XSS annotation popup vulnerability (CVE-2020-12052)</p>
<p>* grafana: XSS via column.title or cellLinkTooltip (CVE-2020-12245)</p>
<p>* grafana: information disclosure through world-readable /var/lib/grafana/grafana.db (CVE-2020-12458)</p>
<p>* grafana: information disclosure through world-readable grafana configuration files (CVE-2020-12459)</p>
<p>* grafana: XSS via the OpenTSDB datasource (CVE-2020-13430)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2020:4682"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2020-11110</id>
    <title>BIT-grafana-2020-11110</title>
    <updated>2026-10-03T17:28:07.418375+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2020-11110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-40387</id>
    <title>EUVD-2026-40387</title>
    <updated>2026-10-03T17:28:07.418400+00:00</updated>
    <content>EUVD-2026-40387</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-40387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-11110</id>
    <title>fkie_cve-2020-11110</title>
    <updated>2026-10-03T17:28:07.418414+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-11110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xr3x-62qw-vc4w</id>
    <title>GHSA-xr3x-62qw-vc4w — Grafana stored XSS</title>
    <updated>2026-10-03T17:28:07.418437+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>Grafana through 6.7.1 allows stored XSS.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xr3x-62qw-vc4w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-11110</id>
    <title>gsd-2020-11110</title>
    <updated>2026-10-03T17:28:07.418456+00:00</updated>
    <content>gsd-2020-11110</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-11110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:4298</id>
    <title>RHSA-2020:4298 — Red Hat Security Advisory: OpenShift Container Platform 4.6.1 image security update</title>
    <updated>2026-10-03T17:28:07.418467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SSL/TLS: CBC padding timing attack (lucky-13) grafana: XSS vulnerability via a column style on the "Dashboard &gt; Table Panel" screen jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection npm-serialize-javascript: XSS via unsafe characters in serialized regular expressions kibana: Prototype pollution in TSVB could result in arbitrary code execution (ESA-2020-06) nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload npmjs-websocket-extensions: ReDoS vulnerability in Sec-WebSocket-Extensions parser nodejs-lodash: prototype pollution in zipObjectDeep function kubernetes: compromised node could escalate to cluster level privileges golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic openshift/console: text injection on error page via crafted url kibana: X-Frame-Option not set by default might lead to clickjacking jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method jquery: Untrusted code execution via &lt;option&gt; tag in HTML passed to DOM manipulation methods grafana: stored XSS grafana: XSS annotation popup vulnerability grafana: XSS via column.title or cellLinkTooltip nodejs-elliptic: improper encoding checks allows a certain degree of signature malleability in ECDSA signatures golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash open…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:4298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:4682</id>
    <title>RHSA-2020:4682 — Red Hat Security Advisory: grafana security, bug fix, and enhancement update</title>
    <updated>2026-10-03T17:28:07.418537+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana: XSS vulnerability via a column style on the "Dashboard &gt; Table Panel" screen grafana: arbitrary file read via MySQL data source grafana: stored XSS grafana: XSS annotation popup vulnerability grafana: XSS via column.title or cellLinkTooltip grafana: information disclosure through world-readable /var/lib/grafana/grafana.db grafana: information disclosure through world-readable grafana configuration files grafana: XSS via the OpenTSDB datasource</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:4682"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:2715-1</id>
    <title>SUSE-SU-2020:2715-1 — Security update for grafana</title>
    <updated>2026-10-03T17:28:07.418567+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for grafana</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:2715-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11110</id>
    <title>UBUNTU-CVE-2020-11110</title>
    <updated>2026-10-03T17:28:07.418582+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-11110"/>
  </entry>
</feed>
