Grafana Labs

First CVE: Mar 1, 2023Active for: 3 years
83
CVEs Published
More CVEs Published than 68% of tracked CNAs
20.8
Avg CVEs / Year
More Avg CVEs / Year than 69% of tracked CNAs
6.4
Avg CVSS Score
Higher Avg CVSS Score than 21% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Grafana Labs as a CNA, 83.1% affect products that Grafana Labs develops as a vendor.

83.1%
16.9%
Self-reported: 69Third-party: 14

Of all the CVEs published that affect products developed by Grafana Labs, 51.9% are self-published by Grafana Labs as a CNA.

51.9%
48.1%
Self-published: 69Published by other CNAs: 64

Trends Over Time

The number and severity of CVEs published by Grafana Labs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2023
3 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by Grafana Labs as a CNA, regardless of affected vendor or product.

83 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website tha
May 22, 20256.189NOYES
The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being pas
Oct 18, 20248.888NOYES
SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifec
Nov 21, 20259.845NONO
An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redir
Jul 18, 20257.645NONO
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so a
Mar 27, 20269.141NONO
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying
Jul 15, 20268.636NONO
We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path traversal/privilege escalation vulnerability in the Grafana O
Jun 13, 20268.836NONO
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana serv
Jun 22, 20268.135NONO
Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configu
Apr 15, 20269.135NONO
The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.
Mar 27, 20267.535NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA83 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local3 (3.6%)
Network80 (96.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low76 (91.6%)
High7 (8.4%)
Unknown0 (0.0%)
User Interaction
None67 (80.7%)
Unknown0 (0.0%)
Required13 (15.7%)
Privileges Required
Low44 (53.0%)
High12 (14.5%)
None27 (32.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (83 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
4.8% of CVEs· 92nd percentile
ExploitDB
1 CVE
1.2% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Grafana Labs as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Grafana Labs as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs