CVE-2019-13068: Grafana

Medium severity, CVSS 5.4. EPSS: 51.9% chance of exploitation in the next 30 days.

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

Affected products

  • Grafana Grafana: before 6.2.5 (fixed in 6.2.5)

Published 2019-06-30. Last modified 2026-06-17.