CVE-2025-2703: Grafana
Medium severity, CVSS 6.8. EPSS: 16% chance of exploitation in the next 30 days.
The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.
Affected products
- Grafana Grafana: from 11.6.0, before 11.6.0+security-01 (fixed in 11.6.0+security-01); from 11.5.0, before 11.5.3+security-01 (fixed in 11.5.3+security-01); from 11.4.0, before 11.4.3+security-01 (fixed in 11.4.3+security-01); from 11.3.0, before 11.3.5+security-01 (fixed in 11.3.5+security-01); from 11.2.0, before 11.2.8+security-01 (fixed in 11.2.8+security-01)
- Grafana Grafana Enterprise: from 11.6.0, before 11.6.0+security-01 (fixed in 11.6.0+security-01); from 11.5.0, before 11.5.3+security-01 (fixed in 11.5.3+security-01); from 11.4.0, before 11.4.3+security-01 (fixed in 11.4.3+security-01); from 11.3.0, before 11.3.5+security-01 (fixed in 11.3.5+security-01); from 11.2.0, before 11.2.8+security-01 (fixed in 11.2.8+security-01)
Published 2025-04-23. Last modified 2026-06-17.