<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:16:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-01605</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-01605</link>
      <description>bdu:2023-01605</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-01605</guid>
    </item>
    <item>
      <title>BIT-grafana-2023-0507</title>
      <link>https://cve.radiocsirt.org/vuln/bit-grafana-2023-0507</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability.&lt;/p&gt;
&lt;p&gt;Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap.&lt;/p&gt;
&lt;p&gt;The stored XSS vulnerability was possible due to map attributions weren&amp;#39;t properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance.&lt;/p&gt;
&lt;p&gt;An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript.&lt;/p&gt;
&lt;p&gt;This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard.&lt;/p&gt;
&lt;p&gt;Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability.&lt;/p&gt;
&lt;p&gt;Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap.&lt;/p&gt;
&lt;p&gt;The stored XSS vulnerability was possible due to map attributions weren&amp;#39;t properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance.&lt;/p&gt;
&lt;p&gt;An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript.&lt;/p&gt;
&lt;p&gt;This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard.&lt;/p&gt;
&lt;p&gt;Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-grafana-2023-0507</guid>
    </item>
    <item>
      <title>EUVD-2026-266785</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266785</link>
      <description>EUVD-2026-266785</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266785</guid>
    </item>
    <item>
      <title>fkie_cve-2023-0507</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0507</link>
      <description>&lt;p&gt;Grafana is an open-source platform for monitoring and observability.&lt;/p&gt;
&lt;p&gt;Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap.&lt;/p&gt;
&lt;p&gt;The stored XSS vulnerability was possible due to map attributions weren&amp;#39;t properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance.&lt;/p&gt;
&lt;p&gt;An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript.&lt;/p&gt;
&lt;p&gt;This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard.&lt;/p&gt;
&lt;p&gt;Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grafana is an open-source platform for monitoring and observability.&lt;/p&gt;
&lt;p&gt;Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap.&lt;/p&gt;
&lt;p&gt;The stored XSS vulnerability was possible due to map attributions weren&amp;#39;t properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance.&lt;/p&gt;
&lt;p&gt;An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript.&lt;/p&gt;
&lt;p&gt;This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard.&lt;/p&gt;
&lt;p&gt;Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-0507</guid>
    </item>
    <item>
      <title>GHSA-hjv9-hm2f-rpcj — Grafana vulnerable to Cross-site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hjv9-hm2f-rpcj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible due to map attributions weren&amp;#39;t properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance. An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript. This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard. Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible due to map attributions weren&amp;#39;t properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance. An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript. This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard. Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hjv9-hm2f-rpcj</guid>
    </item>
    <item>
      <title>gsd-2023-0507</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-0507</link>
      <description>gsd-2023-0507</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-0507</guid>
    </item>
    <item>
      <title>RHSA-2024:0746 — Red Hat Security Advisory: new container image: rhceph-5.3</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0746</link>
      <description>&lt;p&gt;grafana: Use of Cache Containing Sensitive Information golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests haproxy: segfault DoS grafana: cross site scripting grafana: cross site scripting grafana: JWT token leak to data source grafana: stored XSS vulnerability affecting the core plugin &amp;#34;Text&amp;#34; golang: html/template: backticks not treated as string delimiters haproxy: request smuggling attack in HTTP/1 header parsing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grafana: Use of Cache Containing Sensitive Information golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests haproxy: segfault DoS grafana: cross site scripting grafana: cross site scripting grafana: JWT token leak to data source grafana: stored XSS vulnerability affecting the core plugin &amp;#34;Text&amp;#34; golang: html/template: backticks not treated as string delimiters haproxy: request smuggling attack in HTTP/1 header parsing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0746</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:1902-1 — Security update for SUSE Manager Client Tools</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:1902-1</link>
      <description>&lt;p&gt;Security update for SUSE Manager Client Tools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for SUSE Manager Client Tools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:1902-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-0507</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-0507</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible due to map attributions weren&amp;#39;t properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance. An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript. This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard. Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible due to map attributions weren&amp;#39;t properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance. An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript. This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard. Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-0507</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0528 — Grafana: Mehrere Schwachstellen ermöglichen Cross-Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0528</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0528</guid>
    </item>
  </channel>
</rss>
