CVE-2018-18623: Grafana

Medium severity, CVSS 6.1. EPSS: 1.8% chance of exploitation in the next 30 days.

Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

Affected products

  • Grafana Grafana: version 5.3.1 only

Published 2020-06-02. Last modified 2026-06-17.