CVE Tools

Github.com/grafana/grafana

56 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Github.com/grafana/grafana, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Github.com/grafana/grafana CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Github.com/grafana/grafana CVEs per month
MonthCVEs
2024-102
2024-110
2024-120
2025-011
2025-020
2025-030
2025-040
2025-051
2025-063
2025-072
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 56 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical713%
  • High1221%
  • Medium3563%
  • Low24%

Latest CVEs

The 15 most recently published vulnerabilities affecting Github.com/grafana/grafana.

  1. CVE-2025-41115Incorrect privilege assignment10.0
  2. CVE-2025-6023An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chaine...7.6
  3. CVE-2025-3415Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixe...4.3
  4. CVE-2025-1088Very long unicode dashboard title or panel name can hang the frontend2.7
  5. CVE-2025-3454This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauth...5.0
  6. CVE-2025-3260A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, ...8.3
  7. CVE-2025-4123A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a fronten...7.6
  8. CVE-2024-11741Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fi...4.3
  9. CVE-2024-10452Organization admins can delete pending invites created in an organization they are not part of.2.2
  10. CVE-2024-9264Grafana SQL Expressions allow for remote code execution9.9
  11. CVE-2024-6322Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as...5.4
  12. CVE-2024-1313Users outside an organization can delete a snapshot with its key6.5
  13. CVE-2024-1442User with permissions to create a data source can CRUD all data sources6.0
  14. CVE-2023-6152A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only ...5.4
  15. CVE-2023-4822Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in...6.7

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store