CVE-2015-9282: Grafana Piechart-Panel

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard.

Affected products

  • Grafana Piechart-Panel: up to and including 1.3.4

Published 2019-02-06. Last modified 2026-06-17.