Graphite
Graphite · 7 CVEs
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat…
Jun 5, 2026
Graphite Web Absolute Time Range cross site scripting
Dec 24, 2022
Graphite Web Template Name cross site scripting
Dec 24, 2022
Graphite Web Cookie cross site scripting
Dec 24, 2022
graphite-web: graphite.composer.views.send_email vulnerable to SSRF
Oct 11, 2019
Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrar…
Sep 27, 2013
Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrar…
Sep 27, 2013
The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python…
Sep 27, 2013
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-50593 | Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within… | HIGH | 0.16% | Jun 5, 2026 |
| CVE-2022-4730 | Graphite Web Absolute Time Range cross site scripting | MEDIUM | 0.79% | Dec 24, 2022 |
| CVE-2022-4729 | Graphite Web Template Name cross site scripting | MEDIUM | 0.76% | Dec 24, 2022 |
| CVE-2022-4728 | Graphite Web Cookie cross site scripting | MEDIUM | 0.79% | Dec 24, 2022 |
| CVE-2017-18638 | graphite-web: graphite.composer.views.send_email vulnerable to SSRF | HIGH | 15.30% | Oct 11, 2019 |
| CVE-2013-5943 | Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrary web script or HTML via unspecified vec… | MEDIUM | 1.75% | Sep 27, 2013 |
| CVE-2013-5942 | Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object,… | CRITICAL | 2.12% | Sep 27, 2013 |
| CVE-2013-5093 | The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote at… | CRITICAL | 38.67% | Sep 27, 2013 |
Showing 1 to 7 of 7 CVEs