📦 Grafana

by Grafana

🔍 What is Grafana?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-41115

CRITICAL CVSS 10.0 Nov 21, 2025

A critical vulnerability in Grafana's SCIM provisioning allows malicious SCIM clients to provision users with numeric external IDs, potentially overriding internal user IDs. This could lead to imperso...

CVE-2023-3128

CRITICAL CVSS 9.4 Jun 22, 2023

This vulnerability allows attackers to bypass authentication and take over Grafana accounts when Azure AD OAuth is configured with multi-tenant applications. Attackers can modify email claims in Azure...

CVE-2022-28660

CRITICAL CVSS 9.8 May 20, 2022

This vulnerability allows unauthenticated access to Grafana Enterprise Logs querier component when X-Scope-OrgID header is used, bypassing authentication requirements. It affects Grafana Enterprise Lo...

CVE-2022-26148

CRITICAL CVSS 9.8 Mar 21, 2022

This vulnerability exposes Zabbix account passwords in Grafana's HTML source code when integrated with Zabbix. Attackers can discover credentials by viewing page source, potentially compromising the Z...

CVE-2021-41244

CRITICAL CVSS 9.1 Nov 15, 2021

This vulnerability in Grafana allows organization administrators to access and modify users in other organizations when fine-grained access control is enabled. It affects Grafana instances with multip...

CVE-2021-39226

CRITICAL CVSS 9.8 Oct 5, 2021

This vulnerability in Grafana allows unauthenticated or authenticated users to view and delete the snapshot with the lowest database key via specific API endpoints. When public_mode is enabled, unauth...

CVE-2020-27846

CRITICAL CVSS 9.8 Dec 21, 2020

CVE-2020-27846 is a signature verification vulnerability in the crewjam/saml library that allows attackers to bypass SAML authentication. This affects any application using vulnerable versions of this...

CVE-2026-21720

HIGH CVSS 7.5 Jan 27, 2026

This vulnerability in Grafana allows attackers to cause denial of service by exhausting system memory through uncontrolled goroutine creation. Attackers can send sustained requests with random avatar ...

CVE-2025-4123

HIGH CVSS 7.6 May 22, 2025

This CVE describes a cross-site scripting (XSS) vulnerability in Grafana that combines client path traversal with open redirect. Attackers can redirect users to malicious websites hosting frontend plu...

CVE-2023-2801

HIGH CVSS 7.5 Jun 6, 2023

This vulnerability in Grafana allows attackers to crash instances by exploiting mixed queries in public dashboards or directly through the query API. It affects Grafana instances with public dashboard...

CVE-2023-0594

HIGH CVSS 7.3 Mar 1, 2023

Grafana has a stored cross-site scripting (XSS) vulnerability in the trace view visualization that allows attackers with Editor role to inject malicious JavaScript. When an Admin user views a dashboar...

CVE-2022-23498

HIGH CVSS 7.1 Feb 3, 2023

Grafana's datasource query caching feature inadvertently caches session headers, allowing authenticated users to potentially acquire other users' sessions when querying cached datasources. This affect...

CVE-2022-31107

HIGH CVSS 7.1 Jul 15, 2022

This vulnerability allows an authenticated malicious user to take over another user's Grafana account via OAuth login manipulation. It affects Grafana instances with OAuth authentication enabled where...

CVE-2022-31097

HIGH CVSS 7.3 Jul 15, 2022

Grafana versions 8.x and 9.x before specific patched releases are vulnerable to stored cross-site scripting (XSS) in the Unified Alerting feature. An attacker can exploit this to escalate privileges f...

CVE-2022-32276

HIGH CVSS 7.5 Jun 17, 2022

CVE-2022-32276 allows unauthenticated access to Grafana dashboard snapshots via specific URLs, bypassing authentication requirements. This affects Grafana instances with snapshot sharing enabled. The ...

CVE-2022-24812

HIGH CVSS 8.0 Apr 12, 2022

This vulnerability in Grafana Enterprise allows privilege escalation when fine-grained access control is enabled. An attacker can use a lower-privilege API key to inherit cached permissions from a pre...

CVE-2021-43798

HIGH CVSS 7.5 Dec 7, 2021

CVE-2021-43798 is a directory traversal vulnerability in Grafana that allows attackers to read arbitrary files on the server by exploiting a flaw in the plugin URL handling. This affects self-hosted G...

CVE-2021-28148

HIGH CVSS 7.5 Mar 22, 2021

This vulnerability allows unauthenticated attackers to send unlimited requests to a specific Grafana Enterprise API endpoint, causing denial of service (DoS) by overwhelming the server. It affects Gra...

CVE-2021-27358

HIGH CVSS 7.5 Mar 18, 2021

This vulnerability in Grafana's snapshot feature allows unauthenticated remote attackers to trigger a Denial of Service via API calls when a commonly used configuration is enabled. It affects Grafana ...

CVE-2026-21722

MEDIUM CVSS 5.3 Feb 12, 2026

This vulnerability in Grafana allows attackers to view annotation data outside the locked timerange on public dashboards with annotations enabled. Organizations using Grafana with public dashboards an...