VYPR

Geomap panel

by Grafana

CVEs (1)

  • CVE-2026-9029HigJun 22, 2026
    risk 0.47cvss 7.3epss 0.00

    A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).