{"id":"CVE-2020-13429","details":"legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.","modified":"2026-07-08T23:57:59.368646Z","published":"2020-05-24T18:15:10.003Z","related":["SUSE-SU-2021:3174-1","openSUSE-SU-2021:1308-1","openSUSE-SU-2021:3175-1","openSUSE-SU-2024:10819-1"],"references":[{"type":"ADVISORY","url":"https://github.com/grafana/piechart-panel/releases/tag/v1.5.0"},{"type":"REPORT","url":"https://github.com/grafana/piechart-panel/issues/218"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grafana/piechart-panel","events":[{"introduced":"0"},{"fixed":"3234d633402f53640c508dbc5aa48833247434ff"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:grafana:piechart-panel:*:*:*:*:*:grafana:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.5.0"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-13429.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}