Graphite-web
This hub aggregates every CVE we track for Graphite-web, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
LOW3MEDIUM2HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-082026-07
Latest CVEs
The 6 most recently published vulnerabilities affecting Graphite-web.
- CVE-2022-4730Graphite Web Absolute Time Range cross site scripting3.5
- CVE-2022-4728Graphite Web Cookie cross site scripting3.5
- CVE-2022-4729Graphite Web Template Name cross site scripting3.5
- CVE-2017-18638send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server...7.5
- CVE-2013-5942Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to (1) remote_storage.py, (2) ...6.8
- CVE-2013-5093The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via ...6.8
Product normalization is registry-driven with AI assist and human review. How it works