<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:11:13.405318+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-01605</id>
    <title>bdu:2023-01605</title>
    <updated>2026-10-03T18:11:13.678216+00:00</updated>
    <content>bdu:2023-01605</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-01605"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2023-0507</id>
    <title>BIT-grafana-2023-0507</title>
    <updated>2026-10-03T18:11:13.678280+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability.</p>
<p>Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap.</p>
<p>The stored XSS vulnerability was possible due to map attributions weren't properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance.</p>
<p>An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript.</p>
<p>This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard.</p>
<p>Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2023-0507"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266785</id>
    <title>EUVD-2026-266785</title>
    <updated>2026-10-03T18:11:13.678326+00:00</updated>
    <content>EUVD-2026-266785</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0507</id>
    <title>fkie_cve-2023-0507</title>
    <updated>2026-10-03T18:11:13.678340+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Grafana is an open-source platform for monitoring and observability.</p>
<p>Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap.</p>
<p>The stored XSS vulnerability was possible due to map attributions weren't properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance.</p>
<p>An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript.</p>
<p>This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard.</p>
<p>Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-0507"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hjv9-hm2f-rpcj</id>
    <title>GHSA-hjv9-hm2f-rpcj — Grafana vulnerable to Cross-site Scripting</title>
    <updated>2026-10-03T18:11:13.678369+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible due to map attributions weren't properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance. An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript. This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard. Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hjv9-hm2f-rpcj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-0507</id>
    <title>gsd-2023-0507</title>
    <updated>2026-10-03T18:11:13.678399+00:00</updated>
    <content>gsd-2023-0507</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-0507"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0746</id>
    <title>RHSA-2024:0746 — Red Hat Security Advisory: new container image: rhceph-5.3</title>
    <updated>2026-10-03T18:11:13.678410+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana: Use of Cache Containing Sensitive Information golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests haproxy: segfault DoS grafana: cross site scripting grafana: cross site scripting grafana: JWT token leak to data source grafana: stored XSS vulnerability affecting the core plugin "Text" golang: html/template: backticks not treated as string delimiters haproxy: request smuggling attack in HTTP/1 header parsing</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:1902-1</id>
    <title>SUSE-SU-2023:1902-1 — Security update for SUSE Manager Client Tools</title>
    <updated>2026-10-03T18:11:13.678444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for SUSE Manager Client Tools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:1902-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-0507</id>
    <title>UBUNTU-CVE-2023-0507</title>
    <updated>2026-10-03T18:11:13.678460+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible due to map attributions weren't properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance. An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript. This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard. Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-0507"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0528</id>
    <title>WID-SEC-W-2023-0528 — Grafana: Mehrere Schwachstellen ermöglichen Cross-Site Scripting</title>
    <updated>2026-10-03T18:11:13.678483+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0528"/>
  </entry>
</feed>
