CVE-2018-18625: Grafana

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

Affected products

  • Grafana Grafana: version 5.3.1 only

Published 2020-06-02. Last modified 2026-06-17.