FlawAtlas
Search the atlas
CVE-2025-2703 Moderate

CVE-2025-2703

The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.

Exploit probability 17.6%
Published April 25, 2025
Required by Not available
Last source change June 11, 2025

02 / AFFECTED SOFTWARE

Affected packages

Bitnami grafana

04 / EVIDENCE

Source records

Open Source Vulnerabilities BIT-grafana-2025-2703

The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.

View original source

05 / REFERENCES

Further evidence