Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

grafana — Vulnerabilities & Security Advisories 126

Browse all 126 CVE security advisories affecting grafana. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Grafana serves as a leading open-source platform for observability, enabling users to visualize metrics, logs, and traces from diverse data sources. Despite its utility, the software has accumulated 85 recorded Common Vulnerabilities and Exposures (CVEs), reflecting a history of security challenges. Historically, these flaws frequently involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation or improper access controls in its plugin ecosystem and API endpoints. While no single catastrophic incident has defined its entire lifecycle, the high volume of CVEs indicates persistent risks in its complex architecture. Security teams must prioritize regular patching and strict configuration management to mitigate these known weaknesses, ensuring that the platform’s robust visualization capabilities do not compromise underlying infrastructure integrity.

CVE ID Title CVSS Severity Published
CVE-2025-11539 Arbitrary Code Execution in Grafana Image Renderer Plugin — grafana-image-renderer CWE-94 9.9 Critical 2025-10-09
CVE-2025-10630 Regex DoS in Grafana Zabbix Plugin — grafana-zabbix-plugin CWE-20 4.3 Medium 2025-09-19
CVE-2025-8341 SSRF in Infinity Datasource Plugin — grafana-infinity-datasource CWE-918 5.0 Medium 2025-08-04
CVE-2025-6197 Grafana OSS 安全漏洞 — Grafana CWE-601 4.2 Medium 2025-07-18
CVE-2025-6023 Grafana OSS 安全漏洞 — Grafana CWE-601 7.6 High 2025-07-18
CVE-2025-3415 Grafana 安全漏洞 — Grafana CWE-200 4.3 Medium 2025-07-17
CVE-2025-1088 Very long unicode dashboard title or panel name can hang the frontend — Grafana CWE-20 2.7 Low 2025-06-18
CVE-2025-3454 Grafana 安全漏洞 — Grafana CWE-285 5.0 Medium 2025-06-02
CVE-2025-3260 Grafana 安全漏洞 — Grafana CWE-863 8.3 High 2025-06-02
CVE-2025-3580 Grafana OSS 安全漏洞 — Grafana CWE-284 5.5 Medium 2025-05-23
CVE-2025-4123 Grafana 安全漏洞 — Grafana CWE-79 7.6 High 2025-05-22
CVE-2025-2703 Grafana 安全漏洞 — Grafana CWE-79 6.8 Medium 2025-04-23
CVE-2024-11741 Grafana 安全漏洞 — Grafana CWE-200 4.3 Medium 2025-01-31
CVE-2024-10452 Grafana 安全漏洞 — Grafana CWE-639 2.2 Low 2024-10-29
CVE-2024-9264 Grafana SQL Expressions allow for remote code execution — Grafana CWE-94 9.9 Critical 2024-10-18
CVE-2024-8118 Grafana alerting wrong permission on datasource rule write endpoint — Grafana CWE-653 4.3AI Medium AI 2024-09-26
CVE-2024-8996 Grafana Agent Flow on Windows Unquoted service path — Agent Flow CWE-428 7.3 High 2024-09-25
CVE-2024-8975 Grafana Alloy on Windows Unquoted service path — Alloy CWE-428 7.3 High 2024-09-25
CVE-2024-6322 Grafana 安全漏洞 — Grafana CWE-266 4.4 Medium 2024-08-20
CVE-2024-5526 Grafana OnCall 安全漏洞 — OnCall CWE-918 7.7 High 2024-06-05
CVE-2024-1313 Users outside an organization can delete a snapshot with its key — Grafana CWE-639 6.5 Medium 2024-03-26
CVE-2024-1442 User with permissions to create a data source can CRUD all data sources — Grafana CWE-269 6.0 Medium 2024-03-07
CVE-2023-5122 SSRF in CSV Datasource Plugin — grafana-csv-datasource CWE-918 5.0 Medium 2024-02-14
CVE-2023-5123 Improper Path Sanitization in JSON Datasource Plugin — grafana-json-datasource CWE-22 8.0 High 2024-02-14
CVE-2023-6152 Grafana 安全漏洞 — Grafana CWE-863 5.4 Medium 2024-02-13
CVE-2023-3010 Grafana 跨站脚本漏洞 — worldmap-panel CWE-79 7.3 High 2023-10-25
CVE-2023-4399 Grafana 安全漏洞 — Grafana Enterprise CWE-183 6.6 Medium 2023-10-17
CVE-2023-4457 Grafana 安全漏洞 — google-sheets-datasource CWE-209 5.5 Medium 2023-10-16
CVE-2023-4822 Grafana 安全漏洞 — Grafana Enterprise CWE-269 6.7 Medium 2023-10-16
CVE-2023-3128 Grafana 安全漏洞 — Grafana CWE-290 9.4 Critical 2023-06-22

This page lists every published CVE security advisory associated with grafana. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.