Grafana OSS是Grafana公司开源的一个可视化仪表盘。 Grafana OSS 12.4.0版本存在跨站脚本漏洞,该漏洞可能导致编辑器设置文本框变量的默认值为跨站脚本有效载荷。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grafana | Grafana OSS | 12.4.0≤ 12.4.3 |
affected |
13.0.0≤ 13.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grafana | Grafana OSS | 12.4.0 ~ 12.4.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28381 | 9.6 CRITICAL | Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT |
| CVE-2026-42129 | 7.7 HIGH | Path traversal in the Loki data source plugin |
| CVE-2026-42127 | 7.5 HIGH | Pre-authentication denial of service in the public dashboard query endpoint |
| CVE-2026-10601 | 5.4 MEDIUM | Path traversal in the Tempo and Loki data source plugins |
No comments yet