Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
{ "cpes": [ "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*" ], "severity": "Medium" }