github.com/grafana/grafana vulnerabilities
CVEs whose affected-version data names the github.com/grafana/grafana package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
18 CVEsRSS
CVE-2026-27877Medium· 6.5Grafana public dashboards disclose all direct mode datasources
Grafana public dashboards disclose all direct mode datasources
CVE-2026-21724Medium· 5.4Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
CVE-2025-3415Medium· 4.3PoCGrafana's insecure DingDing Alert integration exposes sensitive information
Grafana's insecure DingDing Alert integration exposes sensitive information
CVE-2025-3260High· 8.3Grafana vulnerable to authenticated users bypassing dashboard, folder permissions
Grafana vulnerable to authenticated users bypassing dashboard, folder permissions
CVE-2024-10452Low· 2.2Grafana org admin can delete pending invites in different org
Grafana org admin can delete pending invites in different org
CVE-2021-41244Critical· 9.1Grafana Fine-grained access control vulnerability
Grafana Fine-grained access control vulnerability
CVE-2021-43815Medium· 4.3Grafana directory traversal for .cvs files
Grafana directory traversal for .cvs files
CVE-2023-6152Medium· 5.4Email Validation Bypass And Preventing Sign Up From Email's Owner
Email Validation Bypass And Preventing Sign Up From Email's Owner
CVE-2021-43798High· 7.5CISA KEVPoCGrafana path traversal
Grafana path traversal
CVE-2019-19499Medium· 6.5Grafana Arbitrary File Read
Grafana Arbitrary File Read
CVE-2023-3128Critical· 9.4PoCGrafana vulnerable to Authentication Bypass by Spoofing
Grafana vulnerable to Authentication Bypass by Spoofing
CVE-2023-2183Medium· 4.1Grafana has Broken Access Control in Alert manager: Viewer can send test alerts
Grafana has Broken Access Control in Alert manager: Viewer can send test alerts
CVE-2023-2801High· 7.5Grafana Missing Synchronization vulnerability
Grafana Missing Synchronization vulnerability
CVE-2023-1410Medium· 6.2Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip
Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip
CVE-2023-22462Medium· 6.4Grafana vulnerable to Stored Cross-site Scripting in Text plugin
Grafana vulnerable to Stored Cross-site Scripting in Text plugin
CVE-2020-13430Medium· 6.1Grafana XSS via the OpenTSDB datasource
Grafana XSS via the OpenTSDB datasource
CVE-2020-12458Medium· 5.5Grafana information disclosure
Grafana information disclosure
CVE-2021-39226High· 7.3CISA KEVPoCAuthentication bypass for viewing and deletions of snapshots
Authentication bypass for viewing and deletions of snapshots