graphite project
Enterprise Softwareoss-project
Top products
Latest CVEs
The 8 most recently published vulnerabilities affecting graphite project.
- CVE-2026-50593Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.7.3
- CVE-2022-4730Graphite Web Absolute Time Range cross site scripting3.5
- CVE-2022-4728Graphite Web Cookie cross site scripting3.5
- CVE-2022-4729Graphite Web Template Name cross site scripting3.5
- CVE-2017-18638send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server...7.5
- CVE-2013-5942Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to (1) remote_storage.py, (2) ...6.8
- CVE-2013-5093The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via ...6.8
- CVE-2013-5943Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.4.3