← Back

Grafana

grafana

125 CVEs • 17 products

Products (17)

Click to collapse
Toggle
Grafana
grafana
Tempo
tempo
Loki
loki
Agent
agent
Google Sheets
google_sheets
Worldmap Panel
worldmap_panel
Oncall
oncall
Alloy
alloy
Pyroscope
pyroscope
Snowflake
snowflake

CVEs (125)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Grafana
1Grafana
Jun 17, 2026
Mar 22, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to ad...Show more
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.Show less
1Grafana
1Grafana
Jun 17, 2026
Mar 22, 2021
N/A· v4
7.1 HIGH· v3
4.9 MEDIUM· v2
Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.
2Grafana
Netapp
2E Series Performance Analyzer
Grafana
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
4Fedoraproject
GrafanaRedhat+1 more
6Enterprise Linux
FedoraGrafana+3 more
Jun 17, 2026
Dec 21, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system av...Show more
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.Show less
1Grafana
1Grafana
Jun 17, 2026
Oct 28, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
1Grafana
1Grafana
Jun 17, 2026
Aug 28, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
2Grafana
Netapp
2E Series Performance Analyzer
Grafana
Jun 17, 2026
Jul 27, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard af...Show more
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.Show less
4Fedoraproject
GrafanaNetapp+1 more
5Backports Sle
E Series Performance AnalyzerFedora+2 more
Jun 17, 2026
Jun 3, 2020
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result...Show more
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.Show less
1Grafana
1Grafana
Nov 21, 2024
Jun 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
1Grafana
1Grafana
Nov 21, 2024
Jun 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
1Grafana
1Grafana
Nov 21, 2024
Jun 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
1Grafana
1Grafana
Jun 17, 2026
May 24, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
1Grafana
1Piechart Panel
Jun 17, 2026
May 24, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.
2Fedoraproject
Grafana
2Fedora
Grafana
Jun 17, 2026
Apr 29, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
3Fedoraproject
GrafanaRedhat
4Ceph Storage
Enterprise LinuxFedora+1 more
Jun 17, 2026
Apr 29, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive inform...Show more
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).Show less
1Grafana
1Grafana
Jun 17, 2026
Apr 27, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
1Grafana
1Grafana
Jun 17, 2026
Apr 24, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
1Grafana
1Grafana
Jun 17, 2026
Sep 23, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a...Show more
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.Show less
1Grafana
1Grafana
Jun 17, 2026
Sep 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
1Grafana
1Grafana
Jun 17, 2026
Jun 30, 2019
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).