VYPR

Grafana

by Grafana

Source repositories

CVEs (130)

  • CVE-2024-9476MedNov 13, 2024
    risk 0.33cvss —epss 0.00

    A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who…

  • CVE-2024-8118MedSep 26, 2024
    risk 0.33cvss —epss 0.01

    In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

  • CVE-2023-5122MedFeb 14, 2024
    risk 0.33cvss 5.0epss 0.01

    Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing CSV data from a remote endpoint configured by an administrator. If this plugin was configured…

  • CVE-2023-1410MedMar 23, 2023
    risk 0.33cvss 6.2epss 0.01

    Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An…

  • CVE-2022-31123MedOct 13, 2022
    risk 0.33cvss 6.1epss 0.00

    Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though…

  • CVE-2018-18624MedJun 2, 2020
    risk 0.33cvss 6.1epss 0.01

    Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

  • CVE-2020-12245MedApr 24, 2020
    risk 0.33cvss 6.1epss 0.02

    Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

  • CVE-2019-15635MedSep 23, 2019
    risk 0.32cvss 4.9epss 0.02

    An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction…

  • CVE-2026-33381MedMay 13, 2026
    risk 0.31cvss 5.9epss 0.00

    When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.

  • CVE-2026-8595MedJul 10, 2026
    risk 0.30cvss 6.8epss 0.00

    A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

  • CVE-2020-11110MedJul 27, 2020
    risk 0.29cvss 5.4epss 0.10

    Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

  • CVE-2020-12459MedApr 29, 2020
    risk 0.29cvss 5.5epss 0.00

    In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

  • CVE-2020-12458MedApr 29, 2020
    risk 0.29cvss 5.5epss 0.00

    An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).

  • CVE-2026-10601MedJun 22, 2026
    risk 0.28cvss 5.4epss 0.00

    A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative…

  • CVE-2026-28374MedMay 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.

  • CVE-2026-21724MedMar 26, 2026
    risk 0.28cvss 5.4epss 0.00

    A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

  • CVE-2025-6197MedJul 18, 2025
    risk 0.28cvss 4.2epss 0.72

    An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

  • CVE-2024-6322MedAug 20, 2024
    risk 0.28cvss 5.4epss 0.00

    Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must…

  • CVE-2022-21673MedJan 18, 2022
    risk 0.28cvss 4.3epss 0.02

    Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of…

  • CVE-2018-1000816MedDec 20, 2018
    risk 0.28cvss 5.4epss 0.01

    Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the…

Page 5 of 7