VYPR

Grafana

by Grafana

Source repositories

CVEs (122)

  • CVE-2021-39226CriKEVOct 5, 2021
    risk 0.77cvss 9.8epss 1.00

    Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot…

  • CVE-2022-26148CriMar 21, 2022
    risk 0.68cvss 9.8epss 0.53

    An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search…

  • CVE-2024-9264CriOct 18, 2024
    risk 0.65cvss 9.9epss 0.95

    The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user…

  • CVE-2018-15727CriAug 29, 2018
    risk 0.65cvss 9.8epss 0.64

    Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.

  • CVE-2022-39328CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load.…

  • CVE-2022-28660CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.01

    The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode

  • CVE-2021-43798HigKEVDec 7, 2021
    risk 0.64cvss 7.5epss 0.89

    Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`,…

  • CVE-2023-3128CriJun 22, 2023
    risk 0.61cvss 9.4epss 0.04

    Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

  • CVE-2026-19516CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance,…

  • CVE-2025-41115CriNov 21, 2025
    risk 0.59cvss 10.0epss 0.17

    SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management. In Grafana versions 12.x where SCIM provisioning is enabled and configured, a…

  • CVE-2021-41244CriNov 15, 2021
    risk 0.59cvss 9.1epss 0.03

    Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to access users from other organizations.…

  • CVE-2020-27846CriDec 21, 2020
    risk 0.57cvss 9.8epss 0.05

    A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

  • CVE-2020-13379HigJun 3, 2020
    risk 0.57cvss 8.2epss 1.00

    The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information…

  • CVE-2019-15043HigSep 3, 2019
    risk 0.54cvss 7.5epss 0.63

    In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

  • CVE-2025-4123HigMay 22, 2025
    risk 0.53cvss 7.6epss 0.98

    A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not…

  • CVE-2022-31097HigJul 15, 2022
    risk 0.53cvss 7.3epss 0.69

    Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability…

  • CVE-2026-27876CriMar 27, 2026
    risk 0.52cvss 9.1epss 0.02

    A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only…

  • CVE-2022-24812HigApr 12, 2022
    risk 0.52cvss 8.0epss 0.02

    Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization. Because of the way the…

  • CVE-2026-42127HigJun 22, 2026
    risk 0.49cvss 7.5epss 0.00

    The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid…

  • CVE-2023-2801HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.01

    Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance. The only feature that uses mixed queries at…

Page 1 of 7