vciy

CVEs we hold for Grafana

Records whose assigning authority named Grafana as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9765CVE-2026-9765 CVE RecordGrafana IRM
CVE-2026-9029Stored XSS in the Geomap panel tile-layer attributionGrafana OSS
CVE-2026-8609Pre-authentication denial of service via the OAuth login routeGrafana OSS
CVE-2026-8595Stored XSS in the table panel (TableNG)Grafana OSS
CVE-2026-76154CVE-2026-76154 CVE RecordGrafana Enterprise
CVE-2026-75889CVE-2026-75889 CVE RecordGrafana Alloy
CVE-2026-63087Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpointgrafana-cold-storage oncall
CVE-2026-42129Path traversal in the Loki data source pluginGrafana OSS
CVE-2026-42127Pre-authentication denial of service in the public dashboard query endpointGrafana OSS
CVE-2026-33382Denial of service via unbounded request body sizeGrafana OSS
CVE-2026-33381Users can generate Service Account tokens after permissions removalGrafana OSS
CVE-2026-33380SQL Expressions Read File From DiskGrafana OSS
CVE-2026-33378Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup MacroGrafana OSS
CVE-2026-33377Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard AdminGrafana OSS
CVE-2026-33376Auth Proxy IPv6 whitelist bypassGrafana OSS
CVE-2026-33375Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoSGrafana OSS
CVE-2026-28383Grafana plugin resources can lead to unbounded memory allocationGrafana OSS
CVE-2026-28381Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUTGrafana Snowflake Datasource
CVE-2026-28380BAC in Snapshot API allows deletion of unauthorized dashboard snapshotsGrafana OSS
CVE-2026-28379Viewer-triggered race condition in Grafana Live leads to complete server crashGrafana OSS
CVE-2026-28378Cross-Organization Public Dashboard Deletion via Missing Org IsolationGrafana OSS
CVE-2026-28377S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)Grafana Tempo
CVE-2026-28376Grafana Live push endpoint allows unbounded memory allocation leading to OOMGrafana OSS
CVE-2026-28375Grafana Testdata datasource can issue unbounded memory allocationsGrafana
CVE-2026-28374IDOR in Annotations API allows unprivileged users to DELETE annotationGrafana OSS
CVE-2026-27880OpenFeature evaluation API reads input data with no boundsGrafana
CVE-2026-27879Query resampling can cause unbounded memory allocationsGrafana
CVE-2026-27878Tempo TraceQL query with exemplar hint could result in unbounded memory usageGrafana Tempo
CVE-2026-27877Public dashboards discloses all direct mode datasourcesGrafana
CVE-2026-27876RCE on Grafana via sqlExpressionsGrafana
CVE-2026-21729Loki detected_fields query limits results in unbounded memory allocationGrafana Loki
CVE-2026-21728Tempo query limit results in unbounded memory allocationGrafana Enterprise Traces (GET)
CVE-2026-21727Grafana Correlations: Cross-Tenant Data Disclosure and Permanent Deletion via Legacy org_id=0 RecordGrafana Correlations
CVE-2026-21726Loki Path Traversal - CVE-2021-36156 BypassGrafana Loki
CVE-2026-21725Authorization Bypass via TOCTOU in Grafana Datasource Deletion by NameGrafana
CVE-2026-21724Missing Protected-field Authorization in Provisioning Contact Points APIGrafana OSS
CVE-2026-21723CVE-2026-21723 RecordGrafana OSS
CVE-2026-21722Public Dashboards time range restriction on annotations can be bypassedgrafana/grafana; grafana/grafana-enterprise
CVE-2026-21721Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalationgrafana/grafana; grafana/grafana-enterprise
CVE-2026-21720Unauthenticated DoS: avatar cache leaks goroutines when /avatar/:hash requests time outgrafana/grafana-enterprise; grafana/grafana
CVE-2026-19854CVE-2026-19854 CVE RecordGrafana Clickhouse Datasource
CVE-2026-19516CVE-2026-19516 CVE RecordGrafana mcp-grafana
CVE-2026-19475SQL Data Source Plugin: OOM DoS via $__timeGroup macroGrafana Microsoft SQL Server Datasource
CVE-2026-19197Broken access control in dashboard snapshotsGrafana Enterprise
CVE-2026-17183CVE-2026-17183 CVE RecordGrafana Enterprise
CVE-2026-17033CVE-2026-17033 CVE RecordGrafana OSS
CVE-2026-15815CVE-2026-15815 CVE RecordGrafana Enterprise
CVE-2026-15583SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL headerGrafana MCP Server
CVE-2026-14199Session takeover via Auth Proxy cache key collisionGrafana OSS
CVE-2026-12704SAML assertion replay via skipped InResponseTo validationGrafana Enterprise
CVE-2026-11817CVE-2026-11817 CVE RecordGrafana Enterprise
CVE-2026-11769Operator - Namespaced User Path TraversalGrafana Operator
CVE-2026-10601Path traversal in the Tempo and Loki data source pluginsGrafana OSS
CVE-2025-8341SSRF in Infinity Datasource Plugingrafana-infinity-datasource
CVE-2025-6197no title heldGrafana
CVE-2025-6023no title heldGrafana
CVE-2025-4123no title heldGrafana
CVE-2025-41118Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protectionGrafana Pyroscope
CVE-2025-41117XSS in Grafana Explore stack tracegrafana/grafana; grafana/grafana-enterprise
CVE-2025-41116Incorrect oauth passthrough in Grafana Databricks DatasourceGrafana Databricks Datasource Plugin
CVE-2025-41115Incorrect privilege assignmentGrafana Enterprise
CVE-2025-3717Incorrect oauth passthrough in Grafana Snowflake DatasourceGrafana Snowflake Datasource Plugin
CVE-2025-3580no title heldGrafana
CVE-2025-3454no title heldGrafana; Grafana Enterprise
CVE-2025-3415no title heldGrafana
CVE-2025-3260no title heldGrafana
CVE-2025-2703no title heldGrafana; Grafana Enterprise
CVE-2025-12141Grafana Alerting Editors can edit destination of webhooks they did not createGrafana Alerting
CVE-2025-11539Arbitrary Code Execution in Grafana Image Renderer Plugingrafana-image-renderer
CVE-2025-1088Very long unicode dashboard title or panel name can hang the frontendGrafana
CVE-2025-10630Regex DoS in Grafana Zabbix Plugingrafana-zabbix-plugin
CVE-2024-9476Privilege escalation vulnerability for Organizations in GrafanaGrafana OSS and Enterprise
CVE-2024-9264Grafana SQL Expressions allow for remote code executionGrafana
CVE-2024-8996Grafana Agent Flow on Windows Unquoted service pathGrafana Agent Flow
CVE-2024-8986Information Leakage in grafana-plugin-sdk-gografana-plugin-sdk-go Grafana Plugin SDK
CVE-2024-8975Grafana Alloy on Windows Unquoted service pathGrafana Alloy
CVE-2024-8118Grafana alerting wrong permission on datasource rule write endpointGrafana
CVE-2024-6322no title heldGrafana; Grafana Enterprise
CVE-2024-5526no title heldGrafana OnCall
CVE-2024-1442User with permissions to create a data source can CRUD all data sourcesGrafana
CVE-2024-1313Users outside an organization can delete a snapshot with its keyGrafana
CVE-2024-11741no title heldGrafana
CVE-2024-10452no title heldGrafana
CVE-2023-6152no title heldGrafana; Grafana Enterprise
CVE-2023-5123Improper Path Sanitization in JSON Datasource Plugingrafana-json-datasource
CVE-2023-5122SSRF in CSV Datasource Plugingrafana-csv-datasource
CVE-2023-4822no title heldGrafana Enterprise
CVE-2023-4457no title heldGrafana google-sheets-datasource
CVE-2023-4399no title heldGrafana Enterprise
CVE-2023-3128no title heldGrafana; Grafana Enterprise
CVE-2023-3010no title heldGrafana worldmap-panel
CVE-2023-2801no title heldGrafana; Grafana Enterprise
CVE-2023-22462Stored XSS in Grafana Text plugingrafana
CVE-2023-2183no title heldGrafana; Grafana Enterprise
CVE-2023-1410Stored XSS in Graphite FunctionDescription tooltipGrafana; Grafana Enterprise
CVE-2023-1387no title heldGrafana; Grafana Enterprise
CVE-2023-0594no title heldGrafana; Grafana Enterprise
CVE-2023-0507no title heldGrafana; Grafana Enterprise
CVE-2022-46156Grafana's default installation of `synthetic-monitoring-agent` exposes sensitive informationgrafana synthetic-monitoring-agent
CVE-2022-39328Grafana vulnerable to race condition allowing privilege escalationgrafana
CVE-2022-39324Grafana vulnerable to spoofing originalUrl of snapshotsgrafana
CVE-2022-39307Grafana subject to Exposure of Sensitive Information resulting in User enumeration via forget passwordgrafana
CVE-2022-39306Grafana contains Improper Input Validationgrafana
CVE-2022-39229Grafana users with email as a username can block other users from signing ingrafana
CVE-2022-39201Data source and plugin proxy endpoints could leak the authentication cookie to some destination pluginsgrafana
CVE-2022-36062Grafana folders admin only permission privilege escalationgrafana
CVE-2022-35957Authentication Bypass in Grafana via auth proxy allowing escalation from admin to server admingrafana
CVE-2022-31176Grafana Image Renderer leaking filesgrafana-image-renderer
CVE-2022-31130Grafana data source and plugin proxy endpoints leaking authentication tokens to some destination pluginsgrafana
CVE-2022-31123Grafana plugin signature bypass vulnerabilitygrafana
CVE-2022-31107Grafana account takeover via OAuth vulnerabilitygrafana
CVE-2022-31097Stored XSS in Grafana's Unified Alertinggrafana
CVE-2022-29170Grafana Enterprise datasource network restrictions bypass via HTTP redirectsgrafana
CVE-2022-24812FGAC API Key privilege escalation in Grafanagrafana
CVE-2022-23552Grafana stored XSS in FileUploader componentgrafana
CVE-2022-23498When query caching is enabled in Grafana users can query another users sessiongrafana
CVE-2022-21713Exposure of Sensitive Information in Grafanagrafana
CVE-2022-21703Cross Site Request Forgery in Grafanagrafana
CVE-2022-21702Cross site scripting in Grafana proxygrafana
CVE-2022-21673OAuth Identity Token exposure in Grafanagrafana
CVE-2021-43815Grafana directory traversal for `.cvs` filesgrafana
CVE-2021-43813Directory Traversal in Grafanagrafana
CVE-2021-43798Grafana path traversalgrafana
CVE-2021-41244Cross organization admin control in Grafanagrafana
CVE-2021-41174XSS vulnerability allowing arbitrary JavaScript executiongrafana
CVE-2021-41090Instance config inline secret exposuregrafana agent
CVE-2021-39226Snapshot authentication bypass in grafanagrafana

127 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.