VulnSea

Grafana has 38 CVEs on record between 2021 and 2026. Disclosures have slowed: 4 in the last 90 days after 11 in the 90 before. The busiest recent month was June 2026 with 7. The median CVSS is 6.5 (medium), with 3 rated critical. 5% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-22 (5) and CWE-400 (3). Most affected products: github.com/grafana/grafana (18), grafana (7), Grafana OSS (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
5% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—(2)
Last 90 days
4 prev 11

Products

  • github.com/grafana/grafana 18
  • grafana 7
  • Grafana OSS 3
  • github.com/grafana/tempo 2
  • github.com/grafana/agent 1
  • github.com/grafana/grafana-operator 1
38
Total CVEs
3
Critical
2
CISA KEV
2
Exploited

Grafana vulnerabilities

CVEs affecting Grafana, newest first. Open any entry for full detail, references, and exploit status.

38 CVEsRSS

CVE-2023-2801High· 7.5
3y ago

Grafana Missing Synchronization vulnerability

Grafana Missing Synchronization vulnerability

▾ Twilightgrafana · github.com/grafana/grafanaEPSS 0.74%via OSV
CVE-2023-1410Medium· 6.2
3y ago

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 0.96%via OSV
CVE-2023-22462Medium· 6.4
3y ago

Grafana vulnerable to Stored Cross-site Scripting in Text plugin

Grafana vulnerable to Stored Cross-site Scripting in Text plugin

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.6%via OSV
CVE-2020-13430Medium· 6.1
4y ago

Grafana XSS via the OpenTSDB datasource

Grafana XSS via the OpenTSDB datasource

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 1.8%via OSV
CVE-2020-12458Medium· 5.5
4y ago

Grafana information disclosure

Grafana information disclosure

▾ Sunlitgrafana · github.com/grafana/grafanaEPSS 0.47%via OSV
CVE-2021-41090Medium· 6.5
4y ago

Instance config inline secret exposure in Grafana

Instance config inline secret exposure in Grafana

▾ Sunlitgrafana · github.com/grafana/agentEPSS 0.74%via OSV
CVE-2021-39226High· 7.3CISA KEVPoC
4y ago

Authentication bypass for viewing and deletions of snapshots

Authentication bypass for viewing and deletions of snapshots

▾ Abyssalgrafana · github.com/grafana/grafanaEPSS 100%via OSV
CVE-2021-36156Medium· 5.3
5y ago

Path traversal in Grafana Loki

Path traversal in Grafana Loki

▾ Sunlitgrafana · github.com/grafana/lokiEPSS 1.5%via OSV
Grafana vulnerabilities (CVEs) — page 2 · VulnSea