The built-in XY Chart plugin is vulnerable to a DOM XSS...
Moderate severity
Unreviewed
Published
Jan 15, 2026
to the GitHub Advisory Database
•
Updated Jan 15, 2026
Description
Published by the National Vulnerability Database
Jan 15, 2026
Published to the GitHub Advisory Database
Jan 15, 2026
Last updated
Jan 15, 2026
The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.
References