CVE Tools

Grafana

122 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Grafana, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Grafana CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Grafana CVEs per month
MonthCVEs
2024-102
2024-111
2024-120
2025-011
2025-021
2025-030
2025-041
2025-052
2025-063
2025-073
2025-080
2025-090
2025-100
2025-111
2025-120
2026-012
2026-023
2026-037
2026-044
2026-0510
2026-063
2026-074
2026-080
2026-091

Severity

How the 122 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical119%
  • High3125%
  • Medium7561%
  • Low54%

Latest CVEs

The 15 most recently published vulnerabilities affecting Grafana.

  1. CVE-2026-14199Session takeover via Auth Proxy cache key collision7.1
  2. CVE-2026-8595Stored XSS in the table panel (TableNG)6.8
  3. CVE-2026-8609Pre-authentication denial of service via the OAuth login route5.3
  4. CVE-2026-33382Denial of service via unbounded request body size7.5
  5. CVE-2026-28378Cross-Organization Public Dashboard Deletion via Missing Org Isolation3.1
  6. CVE-2026-42127Pre-authentication denial of service in the public dashboard query endpoint7.5
  7. CVE-2026-9029Stored XSS in the Geomap panel tile-layer attribution7.3
  8. CVE-2026-10601Path traversal in the Tempo and Loki data source plugins5.4
  9. CVE-2026-28374IDOR in Annotations API allows unprivileged users to DELETE annotation4.3
  10. CVE-2026-33378Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup Macro6.5
  11. CVE-2026-28383Grafana plugin resources can lead to unbounded memory allocation6.5
  12. CVE-2026-33376Auth Proxy IPv6 whitelist bypass7.4
  13. CVE-2026-28380BAC in Snapshot API allows deletion of unauthorized dashboard snapshots6.5
  14. CVE-2026-33380SQL Expressions Read File From Disk6.3
  15. CVE-2026-33381Users can generate Service Account tokens after permissions removal5.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store