| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when
extracting plugin archives. A crafted plugin archive can chain relative symbolic link
entries to escape the plugin installation directory, writing arbitrary files and an
executable backend binary outside that directory. The dropped executable runs with the
privileges of the Grafana server process, resulting in remote code execution.
Plugin archives are extracted before their signature is verified, so a valid plugin
signature does not prevent the write. An operator can therefore be affected by
installing a plugin that appears legitimate, as well as by installing a plugin from an
arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or
preinstall configuration.
Grafana Enterprise is affected because it includes the same plugin extraction code as
Grafana OSS. |
| A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin. |
| Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network. |
| External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. |
| Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions. |
| Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions. |
| Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. |
| Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions. |
| Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions. |
| Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML form without escaping. This affects only sites configured to use LdapCommentAuthenticator, and a victim whose session has already loaded the authenticator form must follow a crafted link. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which escapes the reflected values. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a javascript: URI link that survives HTML comment formatting and can execute script in the browser of a visitor who clicks it. This affects only sites that enable HTML in comments (users.comments.htmlenabled=true) together with the HTMLSubset comment formatter; comment moderation, where enabled, delays publication. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which restricts restored links to http, https and mailto URIs. |