CVE-2016-1000220: Elastic Kibana
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.
Affected products
- Elastic Kibana: from 4.1.0, before 4.1.11 (fixed in 4.1.11); from 4.5.0, before 4.5.4 (fixed in 4.5.4)
Published 2017-06-16. Last modified 2026-06-17.