Vendor CVEs
Grafana
All CVEs
165 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-63087 | Cri | 0.00 | 9.8 | 0.01 | Jul 16, 2026 | Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the… | ||
| CVE-2026-21729 | Hig | 0.00 | 7.5 | 0.00 | Jul 16, 2026 | Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. | ||
| CVE-2026-15583 | Hig | 0.00 | 8.6 | 0.01 | Jul 15, 2026 | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services,… | ||
| CVE-2026-32117 | Hig | 0.00 | 7.6 | 0.00 | Mar 11, 2026 | The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly to window.location.assign() / window.open() with no scheme validation. An attacker with dashboard Editor… | ||
| CVE-2022-23552 | Hig | 0.00 | 7.3 | 0.01 | Jan 27, 2023 | Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible because SVG files… | ||
| CVE-2022-31176 | Hig | 0.00 | 8.3 | 0.01 | Sep 2, 2022 | Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to… | ||
| CVE-2022-29170 | Med | 0.00 | 6.6 | 0.01 | May 20, 2022 | Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with… | ||
| CVE-2022-21713 | Med | 0.00 | 4.3 | 0.01 | Feb 8, 2022 | Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the… | ||
| CVE-2022-21703 | Med | 0.00 | 6.3 | 0.02 | Feb 8, 2022 | Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users… | ||
| CVE-2021-36156 | Med | 0.00 | 5.3 | 0.01 | Aug 3, 2021 | An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules… | ||
| CVE-2020-24303 | Med | 0.00 | 6.1 | 0.02 | Oct 28, 2020 | Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource. | ||
| CVE-2018-18625 | Med | 0.00 | 6.1 | 0.01 | Jun 2, 2020 | Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099. | ||
| CVE-2018-18623 | Med | 0.00 | 6.1 | 0.02 | Jun 2, 2020 | Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099. | ||
| CVE-2020-13430 | Med | 0.00 | 6.1 | 0.02 | May 24, 2020 | Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource. | ||
| CVE-2018-12099 | Med | 0.00 | 6.1 | 0.03 | Jun 11, 2018 | Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links. |
- risk 0.00cvss 9.8epss 0.01
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the…
- risk 0.00cvss 7.5epss 0.00
Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.
- risk 0.00cvss 8.6epss 0.01
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services,…
- risk 0.00cvss 7.6epss 0.00
The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly to window.location.assign() / window.open() with no scheme validation. An attacker with dashboard Editor…
- risk 0.00cvss 7.3epss 0.01
Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible because SVG files…
- risk 0.00cvss 8.3epss 0.01
Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to…
- risk 0.00cvss 6.6epss 0.01
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with…
- risk 0.00cvss 4.3epss 0.01
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the…
- risk 0.00cvss 6.3epss 0.02
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users…
- risk 0.00cvss 5.3epss 0.01
An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules…
- risk 0.00cvss 6.1epss 0.02
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
- risk 0.00cvss 6.1epss 0.01
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
- risk 0.00cvss 6.1epss 0.02
Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
- risk 0.00cvss 6.1epss 0.02
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
- risk 0.00cvss 6.1epss 0.03
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
Page 4 of 4