VYPR

Grafana

by Grafana

Source repositories

CVEs (130)

  • CVE-2020-12052MedApr 27, 2020
    risk 0.40cvss 6.1epss 0.01

    Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

  • CVE-2026-17183HigAug 19, 2026
    risk 0.39cvss 7.1epss 0.00

    An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through…

  • CVE-2024-1442MedMar 7, 2024
    risk 0.39cvss 6.0epss 0.01

    A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.

  • CVE-2025-41117MedFeb 12, 2026
    risk 0.37cvss 6.8epss 0.00

    Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected;…

  • CVE-2022-39324MedJan 27, 2023
    risk 0.37cvss 6.7epss 0.01

    Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another user opens the URL of the…

  • CVE-2022-39201MedOct 13, 2022
    risk 0.37cvss 6.8epss 0.01

    Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints…

  • CVE-2025-3580MedMay 23, 2025
    risk 0.36cvss 5.5epss 0.00

    An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An…

  • CVE-2019-19499MedAug 28, 2020
    risk 0.36cvss 6.5epss 0.04

    Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

  • CVE-2025-12141MedApr 15, 2026
    risk 0.35cvss 6.5epss 0.00

    In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic…

  • CVE-2026-28375MedMar 27, 2026
    risk 0.35cvss 6.5epss 0.00

    A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

  • CVE-2026-27879MedMar 27, 2026
    risk 0.35cvss 6.5epss 0.00

    A resample query can be used to trigger out-of-memory crashes in Grafana.

  • CVE-2026-27877MedMar 27, 2026
    risk 0.35cvss 6.5epss 0.00

    When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as…

  • CVE-2026-33375MedMar 26, 2026
    risk 0.35cvss 6.5epss 0.00

    The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container.

  • CVE-2023-6152MedFeb 13, 2024
    risk 0.35cvss 5.4epss 0.01

    A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.

  • CVE-2023-22462MedMar 2, 2023
    risk 0.35cvss 6.4epss 0.02

    Grafana is an open-source platform for monitoring and observability. On 2023-01-01 during an internal audit of Grafana, a member of the security team found a stored XSS vulnerability affecting the core plugin "Text". The stored XSS vulnerability requires several user…

  • CVE-2022-21702MedFeb 8, 2022
    risk 0.35cvss 6.5epss 0.02

    Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting…

  • CVE-2026-11817MedAug 17, 2026
    risk 0.34cvss —epss 0.00

    This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?ac…

  • CVE-2026-21723MedJul 23, 2026
    risk 0.34cvss 5.3epss 0.00

    The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is…

  • CVE-2026-33380MedMay 13, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

  • CVE-2026-21722MedFeb 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did…

Page 4 of 7