VYPR

Vendor CVEs

Grafana

All CVEs

154 total · sorted by risk
  • CVE-2020-12245MedApr 24, 2020
    risk 0.33cvss 6.1epss 0.02

    Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

  • CVE-2015-9282MedFeb 6, 2019
    risk 0.33cvss 6.1epss 0.01

    The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard.

  • CVE-2019-15635MedSep 23, 2019
    risk 0.32cvss 4.9epss 0.02

    An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction…

  • CVE-2026-33381MedMay 13, 2026
    risk 0.31cvss 5.9epss 0.00

    When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.

  • CVE-2026-8595MedJul 10, 2026
    risk 0.30cvss 6.8epss 0.00

    A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

  • CVE-2020-11110MedJul 27, 2020
    risk 0.29cvss 5.4epss 0.10

    Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

  • CVE-2020-12459MedApr 29, 2020
    risk 0.29cvss 5.5epss 0.00

    In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

  • CVE-2020-12458MedApr 29, 2020
    risk 0.29cvss 5.5epss 0.00

    An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).

  • CVE-2026-28374MedMay 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.

  • CVE-2026-21724MedMar 26, 2026
    risk 0.28cvss 5.4epss 0.00

    A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

  • CVE-2025-6197MedJul 18, 2025
    risk 0.28cvss 4.2epss 0.67

    An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

  • CVE-2024-6322MedAug 20, 2024
    risk 0.28cvss 5.4epss 0.00

    Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must…

  • CVE-2022-21673MedJan 18, 2022
    risk 0.28cvss 4.3epss 0.02

    Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of…

  • CVE-2018-1000816MedDec 20, 2018
    risk 0.28cvss 5.4epss 0.01

    Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the…

  • CVE-2026-8609MedJul 10, 2026
    risk 0.27cvss 5.3epss 0.00

    An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

  • CVE-2026-33382HigJul 10, 2026
    risk 0.27cvss 7.5epss 0.00

    Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

  • CVE-2026-21726MedApr 15, 2026
    risk 0.27cvss 5.3epss 0.00

    The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this…

  • CVE-2023-2183MedJun 6, 2023
    risk 0.27cvss 4.1epss 0.01

    Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a test alert using the API as the API…

  • CVE-2023-1387MedApr 26, 2023
    risk 0.27cvss 4.2epss 0.01

    Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it as the authentication token. By enabling the "url_login" configuration…

  • CVE-2025-8341MedAug 4, 2025
    risk 0.26cvss 5.0epss 0.00

    Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafana Labs, allows visualizing data from JSON, CSV, XML, GraphQL, and HTML endpoints. If the plugin was configured to allow only certain URLs, an attacker could…

  • CVE-2025-3454MedJun 2, 2025
    risk 0.26cvss 5.0epss 0.00

    This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. …

  • CVE-2022-31130MedOct 13, 2022
    risk 0.25cvss 4.9epss 0.01

    Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy…

  • CVE-2025-10630MedSep 19, 2025
    risk 0.21cvss 4.3epss 0.00

    Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to visualize monitoring data from Zabbix and create dashboards for analyzing metrics and realtime monitoring.  Versions 5.2.1 and below contained a ReDoS…

  • CVE-2025-3415MedJul 17, 2025
    risk 0.21cvss 4.3epss 0.01

    Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01,…

  • CVE-2025-2842MedApr 2, 2025
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view…

  • CVE-2025-2786MedApr 2, 2025
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to…

  • CVE-2024-11741MedJan 31, 2025
    risk 0.21cvss 4.3epss 0.00

    Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3,  11.2.6, 11.1.11, 11.0.11 and 10.4.15

  • CVE-2022-39229MedOct 13, 2022
    risk 0.21cvss 4.3epss 0.01

    Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s username and email address…

  • CVE-2021-43815MedDec 10, 2021
    risk 0.21cvss 4.3epss 0.02

    Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data source enabled and…

  • CVE-2026-28378LowJul 7, 2026
    risk 0.20cvss 3.1epss 0.00

    The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

  • CVE-2026-21725LowFeb 25, 2026
    risk 0.17cvss 2.6epss 0.00

    A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior…

  • CVE-2026-21727LowApr 15, 2026
    risk 0.14cvss 3.3epss 0.00

    --- title: Cross-Tenant Legacy Correlation Disclosure and Deletion draft: false hero: image: /static/img/heros/hero-legal2.svg content: "# Cross-Tenant Legacy Correlation Disclosure and Deletion" date: 2026-01-29 product: Grafana severity: Low cve: CVE-2026-21727 cvss_score:…

  • CVE-2025-41116LowNov 11, 2025
    risk 0.14cvss epss 0.00

    When using the Grafana Databricks Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it  could result in  the wrong user identifier being used, and information…

  • CVE-2025-3717LowNov 11, 2025
    risk 0.14cvss epss 0.00

    When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it  could result in  the wrong user identifier being used, and information…

  • CVE-2024-10452LowOct 29, 2024
    risk 0.14cvss 2.2epss 0.00

    Organization admins can delete pending invites created in an organization they are not part of.

  • CVE-2025-1088LowJun 18, 2025
    risk 0.11cvss 2.7epss 0.00

    In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.

  • CVE-2021-27358HigMar 18, 2021
    risk 0.07cvss 7.5epss 0.83

    The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

  • CVE-2021-43813MedDec 10, 2021
    risk 0.05cvss 4.3epss 0.57

    Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 contains a directory traversal vulnerability for fully lowercase or fully uppercase .md files. The vulnerability is limited in scope, and only allows access to files…

  • CVE-2026-9765HigJul 24, 2026
    risk 0.00cvss 7.1epss 0.00

    Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and…

  • CVE-2026-63087CriJul 16, 2026
    risk 0.00cvss 9.8epss 0.00

    Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the…

  • CVE-2026-21729HigJul 16, 2026
    risk 0.00cvss 7.5epss 0.00

    Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

  • CVE-2026-15583HigJul 15, 2026
    risk 0.00cvss 8.6epss 0.00

    A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services,…

  • CVE-2026-32117HigMar 11, 2026
    risk 0.00cvss 7.6epss 0.00

    The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly to window.location.assign() / window.open() with no scheme validation. An attacker with dashboard Editor…

  • CVE-2022-23552HigJan 27, 2023
    risk 0.00cvss 7.3epss 0.01

    Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible because SVG files…

  • CVE-2022-31176HigSep 2, 2022
    risk 0.00cvss 8.3epss 0.01

    Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to…

  • CVE-2022-29170MedMay 20, 2022
    risk 0.00cvss 6.6epss 0.01

    Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with…

  • CVE-2022-21713MedFeb 8, 2022
    risk 0.00cvss 4.3epss 0.01

    Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the…

  • CVE-2022-21703MedFeb 8, 2022
    risk 0.00cvss 6.3epss 0.02

    Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users…

  • CVE-2021-36156MedAug 3, 2021
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules…

  • CVE-2020-24303MedOct 28, 2020
    risk 0.00cvss 6.1epss 0.02

    Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.