VYPR

OnCall

by Grafana

CVEs (2)

  • CVE-2024-5526HigJun 5, 2024
    risk 0.50cvss 7.7epss 0.00

    Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces that are tailored specifically for engineers. Grafana OnCall, from version 1.1.37 before 1.5.2 are vulnerable to a Server Side…

  • CVE-2026-63087CriJul 16, 2026
    risk 0.00cvss 9.8epss 0.00

    Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the…