Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Grafana — Vulnerabilities & Security Advisories 111

Browse all 111 CVE security advisories affecting Grafana. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Grafana serves as a leading open-source platform for observability, enabling users to visualize metrics, logs, and traces from diverse data sources. Despite its utility, the software has accumulated 85 recorded Common Vulnerabilities and Exposures (CVEs), reflecting a history of security challenges. Historically, these flaws frequently involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation or improper access controls in its plugin ecosystem and API endpoints. While no single catastrophic incident has defined its entire lifecycle, the high volume of CVEs indicates persistent risks in its complex architecture. Security teams must prioritize regular patching and strict configuration management to mitigate these known weaknesses, ensuring that the platform’s robust visualization capabilities do not compromise underlying infrastructure integrity.

Found 19 results / 111Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-21723 CVE-2026-21723 Record — Grafana OSS 5.3 Medium2026-07-23
CVE-2026-8595 Stored XSS in the table panel (TableNG) — Grafana OSSCWE-79 6.8 Medium2026-07-10
CVE-2026-8609 Pre-authentication denial of service via the OAuth login route — Grafana OSSCWE-400 5.3 Medium2026-07-10
CVE-2026-33382 Denial of service via unbounded request body size — Grafana OSSCWE-400 7.5 High2026-07-10
CVE-2026-9029 Stored XSS in the Geomap panel tile-layer attribution — Grafana OSSCWE-79 7.3 High2026-06-22
CVE-2026-10601 Path traversal in the Tempo and Loki data source plugins — Grafana OSSCWE-22 5.4 Medium2026-06-22
CVE-2026-42129 Path traversal in the Loki data source plugin — Grafana OSSCWE-22 7.7 High2026-06-22
CVE-2026-28374 IDOR in Annotations API allows unprivileged users to DELETE annotation — Grafana OSS 4.3 Medium2026-05-13
CVE-2026-33378 Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup Macro — Grafana OSS 6.5 Medium2026-05-13
CVE-2026-28383 Grafana plugin resources can lead to unbounded memory allocation — Grafana OSS 6.5 Medium2026-05-13
CVE-2026-33376 Auth Proxy IPv6 whitelist bypass — Grafana OSS 7.4 High2026-05-13
CVE-2026-33380 SQL Expressions Read File From Disk — Grafana OSS 6.3 Medium2026-05-13
CVE-2026-28380 BAC in Snapshot API allows deletion of unauthorized dashboard snapshots — Grafana OSS 6.5 Medium2026-05-13
CVE-2026-33381 Users can generate Service Account tokens after permissions removal — Grafana OSS 5.9 Medium2026-05-13
CVE-2026-33377 Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin — Grafana OSS 7.1 High2026-05-13
CVE-2026-28376 Grafana Live push endpoint allows unbounded memory allocation leading to OOM — Grafana OSS 6.5 Medium2026-05-13
CVE-2026-28379 Viewer-triggered race condition in Grafana Live leads to complete server crash — Grafana OSS 6.5 Medium2026-05-13
CVE-2026-21724 Missing Protected-field Authorization in Provisioning Contact Points API — Grafana OSS 5.4 Medium2026-03-26
CVE-2026-33375 Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS — Grafana OSS 6.5 Medium2026-03-26

This page lists every published CVE security advisory associated with Grafana. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.