The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability.
A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.
{
"severity": "Medium",
"cpes": [
"cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:grafana:grafana:*:*:*:*:*:go:*:*"
]
}