Graphite Project maintains a focused monitoring and graphing platform widely embedded in observability infrastructure, where its disclosures center on a single core product and recur through web-layer input-handling and code-injection weaknesses such as cross-site scripting, improper neutralization, code injection, and server-side request forgery. These vulnerability classes reflect the product's role as a web-facing metrics storage and visualization system that parses user input and processes external data sources. Public exploit code frequently becomes available for vulnerabilities in this product; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Graphite Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-5093MEDIUM The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute ar | Sep 27, 2013 | 6.8 | 62 | NO | YES |
CVE-2017-18638HIGH send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Gr | Oct 11, 2019 | 7.5 | 43 | NO | YES |
CVE-2026-50593HIGH Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map | Jun 5, 2026 | 7.3 | 32 | NO | NO |
CVE-2022-4730MEDIUM A vulnerability was found in Graphite Web. It has been classified as problematic. Affected is an unknown function of the component Absolute Time Range Handler. The manipulation lea | Dec 27, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-4728MEDIUM A vulnerability has been found in Graphite Web and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to cro | Dec 27, 2022 | 5.4 | 18 | NO | NO |
CVE-2013-5943MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Sep 27, 2013 | 4.3 | 18 | NO | NO |
CVE-2013-5942MEDIUM Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to (1) remote | Sep 27, 2013 | 6.8 | 18 | NO | NO |
CVE-2022-4729MEDIUM A vulnerability was found in Graphite Web and classified as problematic. This issue affects some unknown processing of the component Template Name Handler. The manipulation leads t | Dec 27, 2022 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Graphite Project.
Media articles that mention a CVE ID that affects a product developed by Graphite Project — matched by CVE ID, not by vendor name.