Grafana Labs
First CVE: Mar 1, 2023Active for: 3 years
83
CVEs Published
More CVEs Published than 68% of tracked CNAs
20.8
Avg CVEs / Year
More Avg CVEs / Year than 69% of tracked CNAs
6.4
Avg CVSS Score
Higher Avg CVSS Score than 21% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Grafana Labs as a CNA, 83.1% affect products that Grafana Labs develops as a vendor.
83.1%
16.9%
Self-reported: 69Third-party: 14
Of all the CVEs published that affect products developed by Grafana Labs, 51.9% are self-published by Grafana Labs as a CNA.
51.9%
48.1%
Self-published: 69Published by other CNAs: 64
Trends Over Time
The number and severity of CVEs published by Grafana Labs over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2023
3 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by Grafana Labs as a CNA, regardless of affected vendor or product.
83 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-4123MEDIUM A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website tha | May 22, 2025 | 6.1 | 89 | NO | YES |
CVE-2024-9264HIGH The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being pas | Oct 18, 2024 | 8.8 | 88 | NO | YES |
CVE-2025-41115CRITICAL SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifec | Nov 21, 2025 | 9.8 | 45 | NO | NO |
CVE-2025-6023HIGH An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0.
The open redir | Jul 18, 2025 | 7.6 | 45 | NO | NO |
CVE-2026-27876CRITICAL A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so a | Mar 27, 2026 | 9.1 | 41 | NO | NO |
CVE-2026-15583HIGH A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying | Jul 15, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-11769HIGH We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path traversal/privilege escalation vulnerability in the Grafana O | Jun 13, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-28381HIGH The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana serv | Jun 22, 2026 | 8.1 | 35 | NO | NO |
CVE-2025-41118CRITICAL Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS).
If the database is configu | Apr 15, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-27880HIGH The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes. | Mar 27, 2026 | 7.5 | 35 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA83 CVEs
8%
49%
34%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (3.6%)
Network80 (96.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low76 (91.6%)
High7 (8.4%)
Unknown0 (0.0%)
User Interaction
None67 (80.7%)
Unknown0 (0.0%)
Required13 (15.7%)
Privileges Required
Low44 (53.0%)
High12 (14.5%)
None27 (32.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (83 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
4.8% of CVEs· 92nd percentile
ExploitDB
1 CVE
1.2% of CVEs· 83rd percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Grafana Labs as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Grafana Labs as a CNA — matched by CVE ID, not by organization name.