VYPR

Geomap panel

by Grafana

Source repositories

CVEs (2)

  • CVE-2026-76154HigSep 17, 2026
    risk 0.40cvss 7.3epss 0.00

    A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.

  • CVE-2026-9029HigJun 22, 2026
    risk 0.40cvss 7.3epss 0.00

    A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).