Grafana has 38 CVEs on record between 2021 and 2026. Disclosures have slowed: 4 in the last 90 days after 11 in the 90 before. The busiest recent month was June 2026 with 7. The median CVSS is 6.5 (medium), with 3 rated critical. 5% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-22 (5) and CWE-400 (3). Most affected products: github.com/grafana/grafana (18), grafana (7), Grafana OSS (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 5% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —(2)
- Last 90 days
- 4 prev 11
Products
- github.com/grafana/grafana 18
- grafana 7
- Grafana OSS 3
- github.com/grafana/tempo 2
- github.com/grafana/agent 1
- github.com/grafana/grafana-operator 1
Worst active — by depth score
CVE-2021-39226High· 7.3Authentication bypass for viewing and deletions of snapshots85CVE-2021-43798High· 7.5Grafana path traversal84CVE-2023-3128Critical· 9.4Grafana vulnerable to Authentication Bypass by Spoofing64CVE-2026-21721High· 8.1The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action57CVE-2021-41244Critical· 9.1Grafana Fine-grained access control vulnerability51
Grafana vulnerabilities
CVEs affecting Grafana, newest first. Open any entry for full detail, references, and exploit status.
38 CVEsRSS
CVE-2023-2801High· 7.5Grafana Missing Synchronization vulnerability
Grafana Missing Synchronization vulnerability
CVE-2023-1410Medium· 6.2Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip
Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip
CVE-2023-22462Medium· 6.4Grafana vulnerable to Stored Cross-site Scripting in Text plugin
Grafana vulnerable to Stored Cross-site Scripting in Text plugin
CVE-2020-13430Medium· 6.1Grafana XSS via the OpenTSDB datasource
Grafana XSS via the OpenTSDB datasource
CVE-2020-12458Medium· 5.5Grafana information disclosure
Grafana information disclosure
CVE-2021-41090Medium· 6.5Instance config inline secret exposure in Grafana
Instance config inline secret exposure in Grafana
CVE-2021-39226High· 7.3CISA KEVPoCAuthentication bypass for viewing and deletions of snapshots
Authentication bypass for viewing and deletions of snapshots
CVE-2021-36156Medium· 5.3Path traversal in Grafana Loki
Path traversal in Grafana Loki