CVE-2020-13429: Grafana Piechart-Panel

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.

Affected products

  • Grafana Piechart-Panel: before 1.5.0 (fixed in 1.5.0)

Published 2020-05-24. Last modified 2026-06-17.