VYPR

Grafana

by Grafana

Source repositories

CVEs (122)

  • CVE-2025-3580MedMay 23, 2025
    risk 0.36cvss 5.5epss 0.00

    An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An…

  • CVE-2019-19499MedAug 28, 2020
    risk 0.36cvss 6.5epss 0.04

    Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

  • CVE-2026-10601MedJun 22, 2026
    risk 0.35cvss 5.4epss 0.00

    A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative…

  • CVE-2025-12141MedApr 15, 2026
    risk 0.35cvss 6.5epss 0.00

    In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic…

  • CVE-2026-28375MedMar 27, 2026
    risk 0.35cvss 6.5epss 0.00

    A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

  • CVE-2026-27879MedMar 27, 2026
    risk 0.35cvss 6.5epss 0.00

    A resample query can be used to trigger out-of-memory crashes in Grafana.

  • CVE-2026-27877MedMar 27, 2026
    risk 0.35cvss 6.5epss 0.00

    When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as…

  • CVE-2026-33375MedMar 26, 2026
    risk 0.35cvss 6.5epss 0.00

    The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container.

  • CVE-2023-6152MedFeb 13, 2024
    risk 0.35cvss 5.4epss 0.01

    A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.

  • CVE-2023-22462MedMar 2, 2023
    risk 0.35cvss 6.4epss 0.02

    Grafana is an open-source platform for monitoring and observability. On 2023-01-01 during an internal audit of Grafana, a member of the security team found a stored XSS vulnerability affecting the core plugin "Text". The stored XSS vulnerability requires several user…

  • CVE-2022-21702MedFeb 8, 2022
    risk 0.35cvss 6.5epss 0.02

    Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting…

  • CVE-2026-21723MedJul 23, 2026
    risk 0.34cvss 5.3epss 0.00

    The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is…

  • CVE-2026-33380MedMay 13, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

  • CVE-2026-21722MedFeb 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did…

  • CVE-2024-9476MedNov 13, 2024
    risk 0.33cvss epss 0.00

    A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who…

  • CVE-2024-8118MedSep 26, 2024
    risk 0.33cvss epss 0.01

    In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

  • CVE-2023-5122MedFeb 14, 2024
    risk 0.33cvss 5.0epss 0.01

    Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing CSV data from a remote endpoint configured by an administrator. If this plugin was configured…

  • CVE-2023-1410MedMar 23, 2023
    risk 0.33cvss 6.2epss 0.01

    Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An…

  • CVE-2022-31123MedOct 13, 2022
    risk 0.33cvss 6.1epss 0.00

    Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though…

  • CVE-2018-18624MedJun 2, 2020
    risk 0.33cvss 6.1epss 0.01

    Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

Page 4 of 7