VYPR

Grafana

by Grafana

Source repositories

CVEs (122)

  • CVE-2022-35957MedSep 20, 2022
    risk 0.43cvss 6.6epss 0.01

    Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the…

  • CVE-2018-19039MedDec 13, 2018
    risk 0.43cvss 6.5epss 0.07

    Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

  • CVE-2026-72585MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission.

  • CVE-2026-33378MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

  • CVE-2026-28383MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service.

  • CVE-2026-28380MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Any Editor could delete any snapshot, even if they have no access to read or write them.

  • CVE-2026-28379MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete service unavailability requiring restart of the Grafana server.

  • CVE-2026-28376MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.

  • CVE-2026-27880HigMar 27, 2026
    risk 0.42cvss 7.5epss 0.01

    The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

  • CVE-2026-21720HigJan 27, 2026
    risk 0.42cvss 7.5epss 0.01

    Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an…

  • CVE-2024-1313MedMar 26, 2024
    risk 0.42cvss 6.5epss 0.01

    It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE request to /api/snapshots/ using its view key. This functionality is intended to only be available to individuals with the…

  • CVE-2022-39306MedNov 9, 2022
    risk 0.42cvss 6.4epss 0.01

    Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. When admins add members to the…

  • CVE-2021-28147MedMar 22, 2021
    risk 0.42cvss 6.5epss 0.02

    The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows…

  • CVE-2021-28146MedMar 22, 2021
    risk 0.42cvss 6.5epss 0.01

    The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to…

  • CVE-2019-13068MedJun 30, 2019
    risk 0.42cvss 5.4epss 0.52

    public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

  • CVE-2020-12052MedApr 27, 2020
    risk 0.40cvss 6.1epss 0.01

    Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

  • CVE-2024-1442MedMar 7, 2024
    risk 0.39cvss 6.0epss 0.01

    A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.

  • CVE-2025-41117MedFeb 12, 2026
    risk 0.37cvss 6.8epss 0.00

    Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected;…

  • CVE-2022-39324MedJan 27, 2023
    risk 0.37cvss 6.7epss 0.01

    Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another user opens the URL of the…

  • CVE-2022-39201MedOct 13, 2022
    risk 0.37cvss 6.8epss 0.01

    Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints…

Page 3 of 7