📦

grafana

Vendor: grafana

Actively Exploited 2 CISA KEV List
PoC / Exploits 10 Code Available
Total RCEs 2 Remote Access
Total CVEs 150 Total Indexed
Avg. EPSS 11.33% Exploit Prob.
Latest CVE CVE-2026-8609 Jul 10

Security Vulnerability Index

Page 10 / 15
6.1 CVSS

Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

EPSS: 1.40%
6.1 CVSS

Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

EPSS: 1.76%
6.1 CVSS

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

EPSS: 1.82%
5.5 CVSS

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

EPSS: 0.32%
5.5 CVSS

An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).

EPSS: 0.47%
6.1 CVSS

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

EPSS: 1.48%
6.1 CVSS

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

EPSS: 1.95%
4.9 CVSS

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

EPSS: 1.61%
7.5 CVSS

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

EPSS: 63.39%
5.4 CVSS
CVE-2019-13068
Exploit Found

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

EPSS: 51.92%