<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:39:18.937914+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10839</id>
    <title>bdu:2026-10839</title>
    <updated>2026-10-02T22:39:19.078661+00:00</updated>
    <content>bdu:2026-10839</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10839"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2026-9029</id>
    <title>BIT-grafana-2026-9029 — Stored XSS in the Geomap panel tile-layer attribution</title>
    <updated>2026-10-02T22:39:19.078709+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2026-9029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-360199</id>
    <title>EUVD-2026-360199</title>
    <updated>2026-10-02T22:39:19.078748+00:00</updated>
    <content>EUVD-2026-360199</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-360199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-9029</id>
    <title>fkie_cve-2026-9029</title>
    <updated>2026-10-02T22:39:19.078762+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-9029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9g84-39mm-q4p3</id>
    <title>GHSA-9g84-39mm-q4p3 — Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug</title>
    <updated>2026-10-02T22:39:19.078786+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before getTemplateSrv().replace() substitutes the variable value, which uses the glob format with no HTML escaping. The result is passed to OpenLayers via element.innerHTML. An Editor can set a textbox variable's default value to an XSS payload that executes for every user who opens the dashboard. This is a bypass of the CVE-2023-0507 fix</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9g84-39mm-q4p3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11619-1</id>
    <title>openSUSE-SU-2026:11619-1 — grafana-12.4.5-4.1 on GA media</title>
    <updated>2026-10-02T22:39:19.078814+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana-12.4.5-4.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11619-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:67573</id>
    <title>RHSA-2026:67573 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T22:39:19.078837+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana: Grafana: Arbitrary code execution and information disclosure via Cross-Site Scripting in geomap panel grafana: tempo: loki: Tempo and Loki Datasource Plugins: Information disclosure and unauthorized actions via path traversal dompurify: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization joi: joi: Prototype Pollution via custom messages</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:67573"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-9029</id>
    <title>UBUNTU-CVE-2026-9029</title>
    <updated>2026-10-02T22:39:19.078860+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-9029"/>
  </entry>
</feed>
