VulnSea

github.com/grafana/grafana vulnerabilities

CVEs whose affected-version data names the github.com/grafana/grafana package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

18 CVEsRSS

CVE-2026-27877Medium· 6.5
5mo ago

Grafana public dashboards disclose all direct mode datasources

Grafana public dashboards disclose all direct mode datasources

Sunlitgrafana · github.com/grafana/grafanaEPSS 0.31%via OSV
CVE-2026-21724Medium· 5.4
6mo ago

Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

Sunlitgrafana · github.com/grafana/grafanaEPSS 0.26%via OSV
CVE-2025-3415Medium· 4.3PoC
1y ago

Grafana's insecure DingDing Alert integration exposes sensitive information

Grafana's insecure DingDing Alert integration exposes sensitive information

Twilightgrafana · github.com/grafana/grafanaEPSS 0.98%via OSV
CVE-2025-3260High· 8.3
1y ago

Grafana vulnerable to authenticated users bypassing dashboard, folder permissions

Grafana vulnerable to authenticated users bypassing dashboard, folder permissions

Twilightgrafana · github.com/grafana/grafanaEPSS 0.56%via OSV
CVE-2024-10452Low· 2.2
1y ago

Grafana org admin can delete pending invites in different org

Grafana org admin can delete pending invites in different org

Sunlitgrafana · github.com/grafana/grafanaEPSS 0.49%via OSV
CVE-2021-41244Critical· 9.1
2y ago

Grafana Fine-grained access control vulnerability

Grafana Fine-grained access control vulnerability

Midnightgrafana · github.com/grafana/grafanaEPSS 2.9%via OSV
CVE-2021-43815Medium· 4.3
2y ago

Grafana directory traversal for .cvs files

Grafana directory traversal for .cvs files

Sunlitgrafana · github.com/grafana/grafanaEPSS 1.8%via OSV
CVE-2023-6152Medium· 5.4
2y ago

Email Validation Bypass And Preventing Sign Up From Email's Owner

Email Validation Bypass And Preventing Sign Up From Email's Owner

Sunlitgrafana · github.com/grafana/grafanaEPSS 1.4%via OSV
CVE-2021-43798High· 7.5CISA KEVPoC
2y ago

Grafana path traversal

Grafana path traversal

Abyssalgrafana · github.com/grafana/grafanaEPSS 89%via OSV
CVE-2019-19499Medium· 6.5
2y ago

Grafana Arbitrary File Read

Grafana Arbitrary File Read

Sunlitgrafana · github.com/grafana/grafanaEPSS 3.6%via OSV
CVE-2023-3128Critical· 9.4PoC
3y ago

Grafana vulnerable to Authentication Bypass by Spoofing

Grafana vulnerable to Authentication Bypass by Spoofing

Abyssalgrafana · github.com/grafana/grafanaEPSS 4.0%via OSV
CVE-2023-2183Medium· 4.1
3y ago

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

Sunlitgrafana · github.com/grafana/grafanaEPSS 1.0%via OSV
CVE-2023-2801High· 7.5
3y ago

Grafana Missing Synchronization vulnerability

Grafana Missing Synchronization vulnerability

Twilightgrafana · github.com/grafana/grafanaEPSS 0.74%via OSV
CVE-2023-1410Medium· 6.2
3y ago

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

Sunlitgrafana · github.com/grafana/grafanaEPSS 0.96%via OSV
CVE-2023-22462Medium· 6.4
3y ago

Grafana vulnerable to Stored Cross-site Scripting in Text plugin

Grafana vulnerable to Stored Cross-site Scripting in Text plugin

Sunlitgrafana · github.com/grafana/grafanaEPSS 1.6%via OSV
CVE-2020-13430Medium· 6.1
4y ago

Grafana XSS via the OpenTSDB datasource

Grafana XSS via the OpenTSDB datasource

Sunlitgrafana · github.com/grafana/grafanaEPSS 1.8%via OSV
CVE-2020-12458Medium· 5.5
4y ago

Grafana information disclosure

Grafana information disclosure

Sunlitgrafana · github.com/grafana/grafanaEPSS 0.47%via OSV
CVE-2021-39226High· 7.3CISA KEVPoC
4y ago

Authentication bypass for viewing and deletions of snapshots

Authentication bypass for viewing and deletions of snapshots

Abyssalgrafana · github.com/grafana/grafanaEPSS 100%via OSV
github.com/grafana/grafana vulnerabilities (CVEs) · VulnSea