[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2022-39324":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T20:55:33.689Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":44,"aliases":45,"duplicate_of":9,"upstream":49,"downstream":50,"duplicates":67,"related":68,"reserved_at":9,"published_at":79,"modified_at":80,"state":81,"summary":82,"references_raw":91,"kevs":134,"epss":135,"epss_history":138,"metrics":402,"affected":420},"CVE-2022-39324","Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another user opens the URL of the snapshot, they will be presented with the regular web interface delivered by the trusted Grafana server. The `Open original dashboard` button no longer points to the to the real original dashboard but to the attacker’s injected URL. This issue is fixed in versions 8.5.16 and 9.2.8.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-79","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.","weakness","Stable","Base","High",[20,24,28,32,36,40],{"id":21,"name":22,"techniques":23},"CAPEC-209","XSS Using MIME Type Mismatch",[],{"id":25,"name":26,"techniques":27},"CAPEC-588","DOM-Based XSS",[],{"id":29,"name":30,"techniques":31},"CAPEC-591","Reflected XSS",[],{"id":33,"name":34,"techniques":35},"CAPEC-592","Stored XSS",[],{"id":37,"name":38,"techniques":39},"CAPEC-63","Cross-Site Scripting (XSS)",[],{"id":41,"name":42,"techniques":43},"CAPEC-85","AJAX Footprinting",[],[],[46,47,48],"GHSA-4724-7jwc-3fpw","BIT-grafana-2022-39324","GO-2024-2867",[],[51,53,55,57,59,61,63,65],{"_key":52},"UBUNTU-CVE-2022-39324",{"_key":54},"SUSE-SU-2023:0811-1",{"_key":56},"SUSE-SU-2024:0191-1",{"_key":58},"SUSE-SU-2024:0196-1",{"_key":60},"SUSE-SU-2023:0812-1",{"_key":62},"SUSE-SU-2023:0821-1",{"_key":64},"OPENSUSE-SU-2024:12659-1",{"_key":66},"RHSA-2023:6420",[],[69,70,71,72,73,74,75,77],{"_key":54},{"_key":56},{"_key":58},{"_key":60},{"_key":62},{"_key":64},{"_key":76},"CGA-C7H2-F55V-9XJR",{"_key":78},"CGA-RQPV-W4HJ-HMFH","2023-01-27T22:42:01.550Z","2026-01-28T04:55:22.240Z","Modified",{"cisa_kev":83,"cisa_ransomware":83,"cisa_vendor":9,"epss_severity":84,"epss_score":85,"severity":86,"severity_score":87,"severity_version":88,"severity_source":89,"severity_vector":90,"severity_status":81},false,"low",0.00185,"medium",6.7,"v3.1","cve.org","CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L",[92,102,109,113,117,121,125,129],{"url":93,"sources":94,"tags":97},"https://github.com/grafana/grafana/security/advisories/GHSA-4724-7jwc-3fpw",[89,95,96],"nvd","osv_go",[98,99,100,101],"X Refsource CONFIRM","Third Party Advisory","WEB","Advisory",{"url":103,"sources":104,"tags":105},"https://github.com/grafana/grafana/pull/60232",[89,95,96],[106,107,99,100,108],"X Refsource MISC","Patch","FIX",{"url":110,"sources":111,"tags":112},"https://github.com/grafana/grafana/pull/60256",[89,95,96],[106,107,99,100,108],{"url":114,"sources":115,"tags":116},"https://github.com/grafana/grafana/commit/239888f22983010576bb3a9135a7294e88c0c74a",[89,95,96],[106,107,99,100,108],{"url":118,"sources":119,"tags":120},"https://github.com/grafana/grafana/commit/d7dcea71ea763780dc286792a0afd560bff2985c",[89,95,96],[106,107,99,100,108],{"url":122,"sources":123,"tags":124},"https://security.netapp.com/advisory/ntap-20230309-0010/",[89,95],[],{"url":126,"sources":127,"tags":128},"https://nvd.nist.gov/vuln/detail/CVE-2022-39324",[96],[101],{"url":130,"sources":131,"tags":132},"https://github.com/grafana/grafana",[96],[133],"PACKAGE",[],{"date":136,"score":85,"percentile":137},"2026-06-05",0.40156,[139,143,146,149,152,155,158,161,164,166,169,172,175,178,181,185,188,191,194,197,201,204,207,210,213,216,219,222,225,228,231,234,237,240,243,245,248,251,254,256,259,262,265,267,270,273,276,279,282,285,288,291,294,297,301,304,307,310,313,316,319,321,323,326,328,331,333,336,338,341,344,346,348,350,353,356,359,362,365,368,371,374,377,380,383,386,389,393,396,399],{"date":140,"score":141,"percentile":142},"2025-11-04",0.00089,0.26189,{"date":144,"score":141,"percentile":145},"2025-11-05",0.2616,{"date":147,"score":141,"percentile":148},"2025-11-06",0.26165,{"date":150,"score":141,"percentile":151},"2025-11-07",0.26164,{"date":153,"score":141,"percentile":154},"2025-11-08",0.26163,{"date":156,"score":141,"percentile":157},"2025-11-09",0.26112,{"date":159,"score":141,"percentile":160},"2025-11-10",0.26075,{"date":162,"score":141,"percentile":163},"2025-11-11",0.26086,{"date":165,"score":141,"percentile":157},"2025-11-12",{"date":167,"score":141,"percentile":168},"2025-11-13",0.26115,{"date":170,"score":141,"percentile":171},"2025-11-14",0.2611,{"date":173,"score":141,"percentile":174},"2025-11-15",0.26104,{"date":176,"score":141,"percentile":177},"2025-11-16",0.2606,{"date":179,"score":141,"percentile":180},"2025-11-17",0.2602,{"date":182,"score":183,"percentile":184},"2025-11-18",0.00929,0.74108,{"date":186,"score":183,"percentile":187},"2025-11-19",0.74115,{"date":189,"score":183,"percentile":190},"2025-11-20",0.74125,{"date":192,"score":141,"percentile":193},"2025-11-21",0.25945,{"date":195,"score":141,"percentile":196},"2025-11-22",0.25943,{"date":198,"score":199,"percentile":200},"2025-11-23",0.0009,0.26116,{"date":202,"score":199,"percentile":203},"2025-11-24",0.26093,{"date":205,"score":199,"percentile":206},"2025-11-25",0.26083,{"date":208,"score":199,"percentile":209},"2025-11-26",0.26073,{"date":211,"score":199,"percentile":212},"2025-11-27",0.26071,{"date":214,"score":199,"percentile":215},"2025-11-28",0.26039,{"date":217,"score":199,"percentile":218},"2025-11-29",0.26029,{"date":220,"score":199,"percentile":221},"2025-11-30",0.25999,{"date":223,"score":199,"percentile":224},"2025-12-01",0.26038,{"date":226,"score":199,"percentile":227},"2025-12-02",0.26063,{"date":229,"score":199,"percentile":230},"2025-12-03",0.26072,{"date":232,"score":199,"percentile":233},"2025-12-04",0.26001,{"date":235,"score":199,"percentile":236},"2025-12-05",0.26037,{"date":238,"score":199,"percentile":239},"2025-12-06",0.26043,{"date":241,"score":199,"percentile":242},"2025-12-07",0.26011,{"date":244,"score":199,"percentile":242},"2025-12-08",{"date":246,"score":199,"percentile":247},"2025-12-09",0.26059,{"date":249,"score":199,"percentile":250},"2025-12-10",0.26127,{"date":252,"score":199,"percentile":253},"2025-12-11",0.26149,{"date":255,"score":199,"percentile":148},"2025-12-12",{"date":257,"score":199,"percentile":258},"2025-12-13",0.26167,{"date":260,"score":199,"percentile":261},"2025-12-14",0.26139,{"date":263,"score":199,"percentile":264},"2025-12-15",0.26114,{"date":266,"score":199,"percentile":250},"2025-12-16",{"date":268,"score":199,"percentile":269},"2025-12-17",0.26185,{"date":271,"score":199,"percentile":272},"2025-12-18",0.26236,{"date":274,"score":199,"percentile":275},"2025-12-19",0.26244,{"date":277,"score":199,"percentile":278},"2025-12-20",0.26211,{"date":280,"score":199,"percentile":281},"2025-12-21",0.26162,{"date":283,"score":199,"percentile":284},"2025-12-22",0.26128,{"date":286,"score":199,"percentile":287},"2025-12-23",0.26095,{"date":289,"score":199,"percentile":290},"2025-12-24",0.26111,{"date":292,"score":199,"percentile":293},"2025-12-25",0.26186,{"date":295,"score":199,"percentile":296},"2025-12-26",0.26176,{"date":298,"score":299,"percentile":300},"2025-12-27",0.0007,0.21643,{"date":302,"score":199,"percentile":303},"2025-12-28",0.26046,{"date":305,"score":199,"percentile":306},"2025-12-29",0.26016,{"date":308,"score":199,"percentile":309},"2025-12-30",0.26015,{"date":311,"score":199,"percentile":312},"2025-12-31",0.26077,{"date":314,"score":199,"percentile":315},"2026-01-01",0.26181,{"date":317,"score":199,"percentile":318},"2026-01-02",0.26178,{"date":320,"score":199,"percentile":281},"2026-01-03",{"date":322,"score":199,"percentile":227},"2026-01-04",{"date":324,"score":199,"percentile":325},"2026-01-05",0.26052,{"date":327,"score":199,"percentile":247},"2026-01-06",{"date":329,"score":199,"percentile":330},"2026-01-07",0.26085,{"date":332,"score":199,"percentile":284},"2026-01-08",{"date":334,"score":199,"percentile":335},"2026-01-09",0.26113,{"date":337,"score":199,"percentile":163},"2026-01-10",{"date":339,"score":199,"percentile":340},"2026-01-11",0.26065,{"date":342,"score":199,"percentile":343},"2026-01-12",0.26019,{"date":345,"score":199,"percentile":221},"2026-01-13",{"date":347,"score":199,"percentile":239},"2026-01-14",{"date":349,"score":199,"percentile":236},"2026-01-15",{"date":351,"score":199,"percentile":352},"2026-01-16",0.2607,{"date":354,"score":199,"percentile":355},"2026-01-17",0.26074,{"date":357,"score":199,"percentile":358},"2026-01-18",0.26024,{"date":360,"score":199,"percentile":361},"2026-01-19",0.25981,{"date":363,"score":199,"percentile":364},"2026-01-20",0.25963,{"date":366,"score":199,"percentile":367},"2026-01-21",0.25909,{"date":369,"score":199,"percentile":370},"2026-01-22",0.25888,{"date":372,"score":199,"percentile":373},"2026-01-23",0.25966,{"date":375,"score":199,"percentile":376},"2026-01-24",0.25968,{"date":378,"score":199,"percentile":379},"2026-01-25",0.25887,{"date":381,"score":199,"percentile":382},"2026-01-26",0.25797,{"date":384,"score":199,"percentile":385},"2026-01-27",0.2578,{"date":387,"score":199,"percentile":388},"2026-01-28",0.25774,{"date":390,"score":391,"percentile":392},"2026-01-29",0.00101,0.28216,{"date":394,"score":391,"percentile":395},"2026-01-30",0.28207,{"date":397,"score":391,"percentile":398},"2026-01-31",0.28211,{"date":400,"score":391,"percentile":401},"2026-02-01",0.28276,[403,408,415],{"source":89,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":404,"cvss_v4_0":9},{"baseScore":87,"baseSeverity":405,"vectorString":90,"impactScore":406,"exploitabilityScore":407},"MEDIUM",9.2,3.1,{"source":95,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":409,"cvss_v4_0":9},{"baseScore":410,"baseSeverity":411,"vectorString":412,"impactScore":413,"exploitabilityScore":414},3.5,"LOW","CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",2.3,5.4,{"source":96,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":416,"cvss_v4_0":417},{"baseScore":87,"baseSeverity":9,"vectorString":90,"impactScore":406,"exploitabilityScore":407},{"baseScore":418,"baseSeverity":9,"vectorString":419,"impactScore":9,"exploitabilityScore":9},5.3,"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L",[421,441],{"ecosystem":422,"name":423,"vendor":424,"product":425,"cpe_part":9,"purl_type":426,"purl_namespace":424,"purl_name":425,"source":9,"versions":427},"Go","github.com/grafana/grafana","github.com/grafana","grafana","golang",[428,436,439],{"version":429,"is_range":430,"range_type":431,"version_start":432,"version_start_type":433,"version_end":434,"version_end_type":435,"fixed_in":9},"gte9_0_0_lt9_2_8",true,"semver","9.0.0","including","9.2.8","excluding",{"version":437,"is_range":430,"range_type":431,"version_start":9,"version_start_type":9,"version_end":438,"version_end_type":435,"fixed_in":9},"lt8_5_16","8.5.16",{"version":440,"is_range":430,"range_type":431,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"all",{"ecosystem":9,"name":425,"vendor":425,"product":425,"cpe_part":442,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":443},"a",[444,447],{"version":445,"is_range":430,"range_type":446,"version_start":9,"version_start_type":9,"version_end":438,"version_end_type":435,"fixed_in":9},"lt8.5.16","cpe",{"version":448,"is_range":430,"range_type":446,"version_start":432,"version_start_type":433,"version_end":434,"version_end_type":435,"fixed_in":9},"gte9.0.0_lt9.2.8"]