Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Grafana OSS — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Grafana OSS, with AI-generated Chinese analysis, references, and POCs.

This page catalogs common weakness enumerations for the Grafana OSS software product. It aggregates security vulnerabilities affecting the open-source version of Grafana, a popular open analytics and interactive visualization web application. The collected data includes diverse vulnerability types such as cross-site scripting, broken access control, and security misconfigurations, spanning from 2018 to the present. This comprehensive collection allows security professionals to track advisory disclosures issued by the vendor and the broader security community over a significant historical period. Users can discover detailed information on how specific weaknesses manifest within the Grafana ecosystem, aiding in risk assessment and patch management. The page serves as a centralized resource to understand the prevalence of certain weakness classes, such as injection or cryptographic failures, specifically within this product context. By organizing these findings, it facilitates the lookup of a product’s vulnerability history, enabling teams to identify recurring security patterns and prioritize remediation efforts based on actual exposure data. This approach supports informed decision-making regarding infrastructure security and compliance monitoring. The content is structured to provide clarity on the nature and impact of each reported flaw without requiring manual searching across multiple sources. It reflects the ongoing evolution of security threats targeting Grafana instances globally.

Vendor: Grafana

CVE IDTitleCVSSSeverityPublished
CVE-2026-21723 CVE-2026-21723 Record 5.3 Medium2026-07-23
CVE-2026-8595 Stored XSS in the table panel (TableNG) CWE-79 6.8 Medium2026-07-10
CVE-2026-8609 Pre-authentication denial of service via the OAuth login route CWE-400 5.3 Medium2026-07-10
CVE-2026-33382 Denial of service via unbounded request body size CWE-400 7.5 High2026-07-10
CVE-2026-9029 Stored XSS in the Geomap panel tile-layer attribution CWE-79 7.3 High2026-06-22
CVE-2026-10601 Path traversal in the Tempo and Loki data source plugins CWE-22 5.4 Medium2026-06-22
CVE-2026-42129 Path traversal in the Loki data source plugin CWE-22 7.7 High2026-06-22
CVE-2026-28374 IDOR in Annotations API allows unprivileged users to DELETE annotation 4.3 Medium2026-05-13
CVE-2026-33378 Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup Macro 6.5 Medium2026-05-13
CVE-2026-28383 Grafana plugin resources can lead to unbounded memory allocation 6.5 Medium2026-05-13
CVE-2026-33376 Auth Proxy IPv6 whitelist bypass 7.4 High2026-05-13
CVE-2026-33380 SQL Expressions Read File From Disk 6.3 Medium2026-05-13
CVE-2026-28380 BAC in Snapshot API allows deletion of unauthorized dashboard snapshots 6.5 Medium2026-05-13
CVE-2026-33381 Users can generate Service Account tokens after permissions removal 5.9 Medium2026-05-13
CVE-2026-33377 Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin 7.1 High2026-05-13
CVE-2026-28376 Grafana Live push endpoint allows unbounded memory allocation leading to OOM 6.5 Medium2026-05-13
CVE-2026-28379 Viewer-triggered race condition in Grafana Live leads to complete server crash 6.5 Medium2026-05-13
CVE-2026-21724 Missing Protected-field Authorization in Provisioning Contact Points API 5.4 Medium2026-03-26
CVE-2026-33375 Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS 6.5 Medium2026-03-26

All 19 known CVE vulnerabilities affecting Grafana OSS with full Chinese analysis, references, and POCs where available.