Medium severity6.1NVD Advisory· Published Feb 6, 2019· Updated Jun 17, 2026
CVE-2015-9282
CVE-2015-9282
Description
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:grafana:piechart-panel:*:*:*:*:*:grafana:*:*+ 1 more
- cpe:2.3:a:grafana:piechart-panel:*:*:*:*:*:grafana:*:*range: <=1.3.4
- (no CPE)range: <=2019-01-02
Patches
Vulnerability mechanics
References
4- github.com/grafana/piechart-panel/pull/163nvdIssue TrackingPatchThird Party Advisory
- padlock.argh.in/2019/02/05/exploiting-xss-grafana.htmlnvdExploitThird Party Advisory
- github.com/grafana/grafana/issues/4117nvdIssue TrackingThird Party Advisory
- github.com/grafana/piechart-panel/issues/3nvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.