📦

grafana

Vendor: grafana

Actively Exploited 2 CISA KEV List
PoC / Exploits 10 Code Available
Total RCEs 2 Remote Access
Total CVEs 150 Total Indexed
Avg. EPSS 11.33% Exploit Prob.
Latest CVE CVE-2026-8609 Jul 10

Security Vulnerability Index

Page 9 / 15
6.5 CVSS

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

EPSS: 1.61%
6.5 CVSS

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

EPSS: 1.40%
7.1 CVSS

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

EPSS: 2.07%
7.5 CVSS

The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

EPSS: 83.04%
9.8 CVSS

A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

EPSS: 4.87%
6.1 CVSS

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

EPSS: 1.96%
6.5 CVSS

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

EPSS: 3.59%
5.4 CVSS

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

EPSS: 9.62%
8.2 CVSS
CVE-2020-13379
Exploit Found

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

EPSS: 99.86%
6.1 CVSS

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

EPSS: 1.19%