Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Grafana MEDIUM 6.1
CVE-2025-41117

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require ma…

Fix: 12.2.4 / 12.3.2+
Fix from $1,600 2026-02-12
Grafana HIGH 8.1
CVE-2026-21721

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who…

Fix: 11.6.9 / 12.0.8+
Fix from $1,950 2026-01-27
Grafana HIGH 7.5
CVE-2026-21720

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer tha…

Fix: 11.6.9 / 12.0.8+
Fix from $1,950 2026-01-27
Grafana CRITICAL 9.8
CVE-2025-41115EPSS 17%

SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i…

Fix: 12.2.1+
Fix from $2,300 2025-11-21
Grafana MEDIUM 6.1
CVE-2025-4123EPSS 98%

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to …

Fix: 10.4.18 / 11.2.9+
Fix from $1,600 2025-05-22
Grafana HIGH 8.8
CVE-2024-9264EPSS 95%

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficie…

Mitigation only
Fix from $1,950 2024-10-18
Alloy HIGH 7.8
CVE-2024-8975

Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Al…

Fix: 1.3.3+
Fix from $1,950 2024-09-25
Agent HIGH 7.8
CVE-2024-8996

Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issu…

Fix: 0.43.2+
Fix from $1,950 2024-09-25
Oncall CRITICAL 9.1
CVE-2024-5526

Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces th…

Fix: 1.5.2+
Fix from $2,300 2024-06-05
Grafana HIGH 8.8
CVE-2024-1442

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user acc…

Fix: 9.5.7 / 10.0.12+
Fix from $1,950 2024-03-07
Json Api Data Source HIGH 8.0
CVE-2023-5123

The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that…

Fix: 1.3.21+
Fix from $1,950 2024-02-14
Grafana MEDIUM 5.3
CVE-2023-5122

Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that a…

Fix: 0.6.13+
Fix from $1,600 2024-02-14
Grafana MEDIUM 5.4
CVE-2023-6152

A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "veri…

Fix: after 2.5.0
Fix from $1,600 2024-02-13
Worldmap Panel MEDIUM 6.1
CVE-2023-3010

Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerabil…

Fix: 1.0.4+
Fix from $1,600 2023-10-25
Grafana HIGH 7.2
CVE-2023-4399

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to c…

Fix: 9.4.17 / 9.5.13+
Fix from $1,950 2023-10-17
Google Sheets HIGH 7.5
CVE-2023-4457

Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are v…

Fix: after 1.2.2
Fix from $1,950 2023-10-16
Grafana HIGH 7.2
CVE-2023-4822

Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allo…

Fix: 9.4.16 / 9.5.11+
Fix from $1,950 2023-10-16
Grafana CRITICAL 9.8
CVE-2023-3128

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. …

Fix: 8.5.27 / 9.2.20+
Fix from $2,300 2023-06-22
Grafana MEDIUM 6.4
CVE-2023-2183

Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for us…

Fix: 8.5.26 / 9.2.19+
Fix from $1,600 2023-06-06
Grafana MEDIUM 5.3
CVE-2023-2801

Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using m…

Fix: 9.4.12 / 9.5.3+
Fix from $1,600 2023-06-06
Grafana HIGH 7.5
CVE-2023-1387

Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a J…

Fix: 9.2.17 / 9.3.13+
Fix from $1,950 2023-04-26
Grafana MEDIUM 5.4
CVE-2023-22462

Grafana is an open-source platform for monitoring and observability. On 2023-01-01 during an internal audit of Grafana, a member of the security team…

Fix: 9.2.10 / 9.3.4+
Fix from $1,600 2023-03-02
Grafana MEDIUM 5.4
CVE-2023-0507EPSS 15%

Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting…

Fix: 8.5.21 / 9.2.13+
Fix from $1,600 2023-03-01
Grafana MEDIUM 5.4
CVE-2023-0594EPSS 9%

Grafana is an open-source platform for monitoring and observability. Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the tr…

Fix: 8.5.21 / 9.2.13+
Fix from $1,600 2023-03-01
Grafana HIGH 8.8
CVE-2022-23498

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including …

Fix: 9.2.10 / 9.3.4+
Fix from $1,950 2023-02-03
Grafana MEDIUM 5.4
CVE-2022-23552

Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Gr…

Fix: 8.5.16 / 9.2.10+
Fix from $1,600 2023-01-27
Enterprise Metrics HIGH 8.8
CVE-2022-44643

A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an acce…

Fix: 1.7.1 / 2.3.1+
Fix from $1,950 2022-12-20
Grafana MEDIUM 5.3
CVE-2022-39307

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the …

Fix: 8.5.15 / 9.2.4+
Fix from $1,600 2022-11-09
Grafana HIGH 8.1
CVE-2022-39306

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper In…

Fix: 8.5.15 / 9.2.4+
Fix from $1,950 2022-11-09
Grafana HIGH 8.1
CVE-2022-39328

Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the…

Fix: 9.2.4+
Fix from $1,950 2022-11-08