{"id":"CVE-2019-13068","aliases":["GHSA-7phr-6cc9-4m5q"],"url":"https://o3.security/vulnerability/CVE-2019-13068","summary":"Grafana Cross-site Scripting vulnerability","details":"public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).","published":"2019-06-30T00:15:11.313Z","modified":"2026-07-08T20:05:24.990452Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},"epss":{"score":0.51915,"percentile":0.98896,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Go","name":"github.com/grafana/grafana","fixedVersion":"6.2.5"}],"fix":null,"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/171500/Grafana-6.2.4-HTML-Injection.html"},{"type":"ADVISORY","url":"https://github.com/grafana/grafana/issues/17718"},{"type":"ADVISORY","url":"https://github.com/grafana/grafana/releases/tag/v6.2.5"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20190710-0001/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:05:24.990452Z"}}