<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:35:26.280170+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-07077</id>
    <title>bdu:2022-07077</title>
    <updated>2026-10-02T18:35:26.506691+00:00</updated>
    <content>bdu:2022-07077</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-07077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2022-31097</id>
    <title>BIT-grafana-2022-31097 — Stored XSS in Grafana's Unified Alerting</title>
    <updated>2026-10-02T18:35:26.506739+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2022-31097"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-649</id>
    <title>certfr-2022-avi-649 — De multiples vulnérabilités ont été découvertes dans Grafana. Elles
permettent à un attaquant de provoquer un contourne…</title>
    <updated>2026-10-02T18:35:26.506776+00:00</updated>
    <content>certfr-2022-avi-649</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-649"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266781</id>
    <title>EUVD-2026-266781</title>
    <updated>2026-10-02T18:35:26.506795+00:00</updated>
    <content>EUVD-2026-266781</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266781"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-31097</id>
    <title>fkie_cve-2022-31097</title>
    <updated>2026-10-02T18:35:26.506807+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-31097"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vw7q-p2qg-4m5f</id>
    <title>GHSA-vw7q-p2qg-4m5f — Grafana Stored Cross-site Scripting in Unified Alerting</title>
    <updated>2026-10-02T18:35:26.506832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>Today we are releasing Grafana 8.3.10, 8.4.10, 8.5.9 and 9.0.3. This patch release includes a HIGH severity security fix for a stored Cross Site Scripting in Grafana.</p>
<p>Release v.9.0.3, containing this security fix and other patches:</p>
<p>- [Download Grafana 9.0.3](https://grafana.com/grafana/download/9.0.3)
- [Release notes](https://grafana.com/docs/grafana/next/release-notes/release-notes-9-0-3/)</p>
<p>Release v.8.5.9, containing this security fix and other fixes:</p>
<p>- [Download Grafana 8.5.9](https://grafana.com/grafana/download/8.5.9)
- [Release notes](https://grafana.com/docs/grafana/next/release-notes/release-notes-8-5-9/)</p>
<p>Release v.8.4.10, containing this security fix and other fixes:</p>
<p>- [Download Grafana 8.4.10](https://grafana.com/grafana/download/8.4.10)
- [Release notes](https://grafana.com/docs/grafana/next/release-notes/release-notes-8-4-10/)</p>
<p>Release v.8.3.10, containing this security fix and other fixes:</p>
<p>- [Download Grafana 8.3.10](https://grafana.com/grafana/download/8.3.10)</p>
<p>## Stored XSS ([CVE-2022-31097](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31097))</p>
<p>### Summary
On June 19 a security researcher contacted Grafana Labs to disclose a XSS vulnerability in the Unified Alerting feature of Grafana. After analysis, this stored XSS could be used to elevate privileges from Editor to Admin.</p>
<p>We believe that this vulnerability is rated at CVSS 7.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N).</p>
<p>### Impact
An attacker can exploit this vulnerability to escalat…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vw7q-p2qg-4m5f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-31097</id>
    <title>gsd-2022-31097</title>
    <updated>2026-10-02T18:35:26.506888+00:00</updated>
    <content>gsd-2022-31097</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-31097"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1186</id>
    <title>OESA-2025-1186 — grafana security update</title>
    <updated>2026-10-02T18:35:26.506902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: grafana</p>
<p>Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp;amp; OpenTSDB.

Security Fix(es):</p>
<p>Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.(CVE-2022-31097)</p>
<p>Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.(CVE-2022-31123)</p>
<p>Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user&amp;apos;s Grafana…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1186"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12260-1</id>
    <title>openSUSE-SU-2024:12260-1 — grafana-8.3.10-1.1 on GA media</title>
    <updated>2026-10-02T18:35:26.506957+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana-8.3.10-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12260-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:3642</id>
    <title>RHSA-2023:3642 — Red Hat Security Advisory: Red Hat Ceph Storage 6.1 Container security and bug fix update</title>
    <updated>2026-10-02T18:35:26.506977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ramda: prototype poisoning eventsource: Exposure of Sensitive Information golang: net/http: improper sanitization of Transfer-Encoding header golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters marked: regular expression block.def may lead Denial of Service marked: regular expression inline.reflinkSearch may lead Denial of Service grafana: Use of Cache Containing Sensitive Information golang: encoding/pem: fix stack overflow in Decode Moment.js: Path traversal  in moment.locale grafana: An information leak issue was discovered in Grafana through 7.3.4, when integrated with Zabbix golang: net/http: handle server errors after sending GOAWAY golang: encoding/xml: stack exhaustion in Decoder.Skip golang: crypto/elliptic: panic caused by oversized scalar golang: syscall: faccessat checks wrong group golang: crypto/tls: session tickets lack random ticket_age_add golang: io/fs: stack exhaustion in Glob golang: compress/gzip: stack exhaustion in Reader.Read golang: path/filepath: stack exhaustion in Glob golang: encoding/xml: stack exhaustion in Unmarshal golang: encoding/gob: stack exhaustion in Decoder.Decode grafana: stored XSS vulnerability grafana: OAuth account takeover grafana: plugin signature bypass grafana: data source and plugin proxy endpoints leaking authentication tokens to some destination plugins golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working golang: math/big: decoding big.Float and big.Rat…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:3642"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3676-1</id>
    <title>SUSE-SU-2022:3676-1 — Security update for grafana</title>
    <updated>2026-10-02T18:35:26.507052+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for grafana</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3676-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-31097</id>
    <title>UBUNTU-CVE-2022-31097</title>
    <updated>2026-10-02T18:35:26.507074+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-31097"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0696</id>
    <title>WID-SEC-W-2022-0696 — Grafana: Mehrere Schwachstellen</title>
    <updated>2026-10-02T18:35:26.507094+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen und Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0696"/>
  </entry>
</feed>
