The built-in XY Chart plugin is vulnerable to a DOM XSS...
Moderate severity
Unreviewed
Published
Apr 23, 2025
to the GitHub Advisory Database
•
Updated Jun 10, 2025
Description
Published by the National Vulnerability Database
Apr 23, 2025
Published to the GitHub Advisory Database
Apr 23, 2025
Last updated
Jun 10, 2025
The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability.
A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.
References