[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2018-18625":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":44,"aliases":54,"duplicate_of":9,"upstream":57,"downstream":58,"duplicates":69,"related":70,"reserved_at":9,"published_at":75,"modified_at":76,"state":77,"summary":78,"references_raw":86,"kevs":121,"epss":122,"epss_history":125,"metrics":377,"affected":390},"CVE-2018-18625","Grafana 5.3.1 has XSS via a link on the \"Dashboard > All Panels > General\" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-79","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.","weakness","Stable","Base","High",[20,24,28,32,36,40],{"id":21,"name":22,"techniques":23},"CAPEC-209","XSS Using MIME Type Mismatch",[],{"id":25,"name":26,"techniques":27},"CAPEC-588","DOM-Based XSS",[],{"id":29,"name":30,"techniques":31},"CAPEC-591","Reflected XSS",[],{"id":33,"name":34,"techniques":35},"CAPEC-592","Stored XSS",[],{"id":37,"name":38,"techniques":39},"CAPEC-63","Cross-Site Scripting (XSS)",[],{"id":41,"name":42,"techniques":43},"CAPEC-85","AJAX Footprinting",[],[45],{"_key":46,"name":47,"source":48,"url":49,"maturity":50,"reliability_score":51,"verified":52,"type":9,"platforms":53,"requires_auth":9,"exploitdb":9,"metasploit":9},"GITHUB_GRAFANA_GRAFANA","Grafana","github","https://github.com/grafana/grafana/issues/13667","poc",0.3,false,[],[55,56],"GHSA-6wh2-8hw7-jw94","GO-2024-2483",[],[59,61,63,65,67],{"_key":60},"UBUNTU-CVE-2018-18625",{"_key":62},"SUSE-SU-2020:2876-1",{"_key":64},"SUSE-SU-2020:2911-1",{"_key":66},"SUSE-SU-2020:3309-1",{"_key":68},"SUSE-SU-2021:1962-1",[],[71,72,73,74],{"_key":62},{"_key":64},{"_key":66},{"_key":68},"2020-06-02T16:41:00.000Z","2024-08-05T11:16:00.190Z","Modified",{"cisa_kev":52,"cisa_ransomware":52,"cisa_vendor":9,"epss_severity":79,"epss_score":80,"severity":81,"severity_score":82,"severity_version":83,"severity_source":84,"severity_vector":85,"severity_status":77},"low",0.00825,"medium",6.1,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",[87,99,104,109,113,117],{"url":88,"sources":89,"tags":92},"https://github.com/grafana/grafana/pull/11813",[90,84,91],"cve.org","osv_go",[93,94,95,96,97,98],"X Refsource MISC","Exploit","Patch","Third Party Advisory","WEB","FIX",{"url":100,"sources":101,"tags":102},"https://security.netapp.com/advisory/ntap-20200608-0008/",[90,84],[103],"X Refsource CONFIRM",{"url":105,"sources":106,"tags":107},"https://nvd.nist.gov/vuln/detail/CVE-2018-18625",[91],[108],"Advisory",{"url":110,"sources":111,"tags":112},"https://github.com/grafana/grafana/pull/14984",[91],[97,98],{"url":114,"sources":115,"tags":116},"https://security.netapp.com/advisory/ntap-20200608-0008",[91],[97],{"url":118,"sources":119,"tags":120},"https://github.com/advisories/GHSA-6wh2-8hw7-jw94",[91],[108],[],{"date":123,"score":80,"percentile":124},"2026-06-04",0.74819,[126,129,132,135,138,140,143,146,149,152,155,158,161,163,166,170,173,176,179,182,184,187,190,193,195,197,200,202,205,208,210,213,215,217,219,221,224,227,230,233,236,239,242,244,247,250,253,256,259,261,264,266,269,272,275,278,281,283,286,289,291,294,296,299,302,305,308,311,314,317,320,323,325,328,331,334,337,340,343,346,349,352,355,357,360,363,366,368,371,374],{"date":127,"score":80,"percentile":128},"2025-11-04",0.73707,{"date":130,"score":80,"percentile":131},"2025-11-05",0.73691,{"date":133,"score":80,"percentile":134},"2025-11-06",0.73688,{"date":136,"score":80,"percentile":137},"2025-11-07",0.73706,{"date":139,"score":80,"percentile":137},"2025-11-08",{"date":141,"score":80,"percentile":142},"2025-11-09",0.73701,{"date":144,"score":80,"percentile":145},"2025-11-10",0.73687,{"date":147,"score":80,"percentile":148},"2025-11-11",0.73692,{"date":150,"score":80,"percentile":151},"2025-11-12",0.73711,{"date":153,"score":80,"percentile":154},"2025-11-13",0.73719,{"date":156,"score":80,"percentile":157},"2025-11-14",0.73725,{"date":159,"score":80,"percentile":160},"2025-11-15",0.73723,{"date":162,"score":80,"percentile":154},"2025-11-16",{"date":164,"score":80,"percentile":165},"2025-11-17",0.73712,{"date":167,"score":168,"percentile":169},"2025-11-18",0.00563,0.65809,{"date":171,"score":168,"percentile":172},"2025-11-19",0.65819,{"date":174,"score":168,"percentile":175},"2025-11-20",0.65812,{"date":177,"score":80,"percentile":178},"2025-11-21",0.73731,{"date":180,"score":80,"percentile":181},"2025-11-22",0.73722,{"date":183,"score":80,"percentile":137},"2025-11-23",{"date":185,"score":80,"percentile":186},"2025-11-24",0.73702,{"date":188,"score":80,"percentile":189},"2025-11-25",0.73704,{"date":191,"score":80,"percentile":192},"2025-11-26",0.7371,{"date":194,"score":80,"percentile":165},"2025-11-27",{"date":196,"score":80,"percentile":189},"2025-11-28",{"date":198,"score":80,"percentile":199},"2025-11-29",0.73696,{"date":201,"score":80,"percentile":131},"2025-11-30",{"date":203,"score":80,"percentile":204},"2025-12-01",0.73823,{"date":206,"score":80,"percentile":207},"2025-12-02",0.73829,{"date":209,"score":80,"percentile":207},"2025-12-03",{"date":211,"score":80,"percentile":212},"2025-12-04",0.73698,{"date":214,"score":80,"percentile":128},"2025-12-05",{"date":216,"score":80,"percentile":137},"2025-12-06",{"date":218,"score":80,"percentile":137},"2025-12-07",{"date":220,"score":80,"percentile":151},"2025-12-08",{"date":222,"score":80,"percentile":223},"2025-12-09",0.73742,{"date":225,"score":80,"percentile":226},"2025-12-10",0.73774,{"date":228,"score":80,"percentile":229},"2025-12-11",0.73791,{"date":231,"score":80,"percentile":232},"2025-12-12",0.73813,{"date":234,"score":80,"percentile":235},"2025-12-13",0.73817,{"date":237,"score":80,"percentile":238},"2025-12-14",0.73815,{"date":240,"score":80,"percentile":241},"2025-12-15",0.73819,{"date":243,"score":80,"percentile":207},"2025-12-16",{"date":245,"score":80,"percentile":246},"2025-12-17",0.7384,{"date":248,"score":80,"percentile":249},"2025-12-18",0.73863,{"date":251,"score":80,"percentile":252},"2025-12-19",0.7388,{"date":254,"score":80,"percentile":255},"2025-12-20",0.73878,{"date":257,"score":80,"percentile":258},"2025-12-21",0.73871,{"date":260,"score":80,"percentile":258},"2025-12-22",{"date":262,"score":80,"percentile":263},"2025-12-23",0.7386,{"date":265,"score":80,"percentile":258},"2025-12-24",{"date":267,"score":80,"percentile":268},"2025-12-25",0.73899,{"date":270,"score":80,"percentile":271},"2025-12-26",0.73895,{"date":273,"score":80,"percentile":274},"2025-12-27",0.73924,{"date":276,"score":80,"percentile":277},"2025-12-28",0.73873,{"date":279,"score":80,"percentile":280},"2025-12-29",0.73865,{"date":282,"score":80,"percentile":252},"2025-12-30",{"date":284,"score":80,"percentile":285},"2025-12-31",0.73909,{"date":287,"score":80,"percentile":288},"2026-01-01",0.74057,{"date":290,"score":80,"percentile":288},"2026-01-02",{"date":292,"score":80,"percentile":293},"2026-01-03",0.74059,{"date":295,"score":80,"percentile":274},"2026-01-04",{"date":297,"score":80,"percentile":298},"2026-01-05",0.73916,{"date":300,"score":80,"percentile":301},"2026-01-06",0.73931,{"date":303,"score":80,"percentile":304},"2026-01-07",0.7394,{"date":306,"score":80,"percentile":307},"2026-01-08",0.73952,{"date":309,"score":80,"percentile":310},"2026-01-09",0.73959,{"date":312,"score":80,"percentile":313},"2026-01-10",0.73955,{"date":315,"score":80,"percentile":316},"2026-01-11",0.73943,{"date":318,"score":80,"percentile":319},"2026-01-12",0.73932,{"date":321,"score":80,"percentile":322},"2026-01-13",0.7393,{"date":324,"score":80,"percentile":313},"2026-01-14",{"date":326,"score":80,"percentile":327},"2026-01-15",0.73966,{"date":329,"score":80,"percentile":330},"2026-01-16",0.73982,{"date":332,"score":80,"percentile":333},"2026-01-17",0.7398,{"date":335,"score":80,"percentile":336},"2026-01-18",0.73956,{"date":338,"score":80,"percentile":339},"2026-01-19",0.73944,{"date":341,"score":80,"percentile":342},"2026-01-20",0.73948,{"date":344,"score":80,"percentile":345},"2026-01-21",0.73951,{"date":347,"score":80,"percentile":348},"2026-01-22",0.73957,{"date":350,"score":80,"percentile":351},"2026-01-23",0.73988,{"date":353,"score":80,"percentile":354},"2026-01-24",0.73997,{"date":356,"score":80,"percentile":333},"2026-01-25",{"date":358,"score":80,"percentile":359},"2026-01-26",0.73978,{"date":361,"score":80,"percentile":362},"2026-01-27",0.73983,{"date":364,"score":80,"percentile":365},"2026-01-28",0.73995,{"date":367,"score":80,"percentile":365},"2026-01-29",{"date":369,"score":80,"percentile":370},"2026-01-30",0.74,{"date":372,"score":80,"percentile":373},"2026-01-31",0.74005,{"date":375,"score":80,"percentile":376},"2026-02-01",0.74131,[378,388],{"source":84,"cvss_v2_0":379,"cvss_v3_0":9,"cvss_v3_1":384,"cvss_v4_0":9},{"baseScore":380,"baseSeverity":9,"vectorString":381,"impactScore":382,"exploitabilityScore":383},4.3,"AV:N/AC:M/Au:N/C:N/I:P/A:N",2.9,8.6,{"baseScore":82,"baseSeverity":385,"vectorString":85,"impactScore":386,"exploitabilityScore":387},"MEDIUM",4.5,7.2,{"source":91,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":389,"cvss_v4_0":9},{"baseScore":82,"baseSeverity":9,"vectorString":85,"impactScore":386,"exploitabilityScore":387},[391,407],{"ecosystem":392,"name":393,"vendor":394,"product":395,"cpe_part":9,"purl_type":396,"purl_namespace":394,"purl_name":395,"source":9,"versions":397},"Go","github.com/grafana/grafana","github.com/grafana","grafana","golang",[398,404],{"version":399,"is_range":400,"range_type":401,"version_start":9,"version_start_type":9,"version_end":402,"version_end_type":403,"fixed_in":9},"lt6_0_0_beta1",true,"semver","6.0.0-beta1","excluding",{"version":405,"is_range":400,"range_type":401,"version_start":9,"version_start_type":9,"version_end":406,"version_end_type":403,"fixed_in":9},"lt6_0_0_beta1+incompatible","6.0.0-beta1+incompatible",{"ecosystem":9,"name":395,"vendor":395,"product":395,"cpe_part":408,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":409},"a",[410],{"version":411,"is_range":52,"range_type":412,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"5.3.1","cpe"]