VYPR

Vendor CVEs

Grafana

All CVEs

165 total · sorted by risk
  • CVE-2026-63087CriJul 16, 2026
    risk 0.00cvss 9.8epss 0.01

    Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the…

  • CVE-2026-21729HigJul 16, 2026
    risk 0.00cvss 7.5epss 0.00

    Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

  • CVE-2026-15583HigJul 15, 2026
    risk 0.00cvss 8.6epss 0.01

    A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services,…

  • CVE-2026-32117HigMar 11, 2026
    risk 0.00cvss 7.6epss 0.00

    The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly to window.location.assign() / window.open() with no scheme validation. An attacker with dashboard Editor…

  • CVE-2022-23552HigJan 27, 2023
    risk 0.00cvss 7.3epss 0.01

    Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible because SVG files…

  • CVE-2022-31176HigSep 2, 2022
    risk 0.00cvss 8.3epss 0.01

    Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to…

  • CVE-2022-29170MedMay 20, 2022
    risk 0.00cvss 6.6epss 0.01

    Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with…

  • CVE-2022-21713MedFeb 8, 2022
    risk 0.00cvss 4.3epss 0.01

    Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the…

  • CVE-2022-21703MedFeb 8, 2022
    risk 0.00cvss 6.3epss 0.02

    Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users…

  • CVE-2021-36156MedAug 3, 2021
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules…

  • CVE-2020-24303MedOct 28, 2020
    risk 0.00cvss 6.1epss 0.02

    Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

  • CVE-2018-18625MedJun 2, 2020
    risk 0.00cvss 6.1epss 0.01

    Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

  • CVE-2018-18623MedJun 2, 2020
    risk 0.00cvss 6.1epss 0.02

    Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

  • CVE-2020-13430MedMay 24, 2020
    risk 0.00cvss 6.1epss 0.02

    Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

  • CVE-2018-12099MedJun 11, 2018
    risk 0.00cvss 6.1epss 0.03

    Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.

Page 4 of 4