Grafana Labs maintains a widely deployed observability platform spanning dashboarding, monitoring agents, metrics storage, and log aggregation products that sit on the perimeter between trusted infrastructure and user-facing interfaces. Despite a focused product portfolio, the vendor's prominence in the landscape reflects the central role these tools play in visibility and alerting across enterprise environments. Vulnerabilities affecting the vendor skew toward moderate severity and frequently acquire public exploit code; the exposure recurs through web-application and access-control weakness classes including cross-site scripting, information disclosure, path traversal, and authorization flaws that are characteristic of services exposed to both internal and external networks. Defenders should prioritize patches for internet-facing instances and authentication-boundary services; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Grafana Labs over time
Of all the CVEs published by Grafana Labs as a CNA, 83.1% affect products that Grafana Labs develops as a vendor.
Of all the CVEs published that affect products developed by Grafana Labs, 51.9% are self-published by Grafana Labs as a CNA.
Signals from CVEs in this vendor scope (133 CVEs).
133 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43798HIGH Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, | Dec 7, 2021 | 7.5 | 98 | YES | YES |
CVE-2021-39226HIGH Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by ac | Oct 5, 2021 | 7.3 | 97 | YES | YES |
CVE-2020-13379HIGH The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP re | Jun 3, 2020 | 8.2 | 90 | NO | YES |
CVE-2025-4123MEDIUM A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website tha | May 22, 2025 | 6.1 | 89 | NO | YES |
CVE-2024-9264HIGH The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being pas | Oct 18, 2024 | 8.8 | 88 | NO | YES |
CVE-2021-27358HIGH The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configurat | Mar 18, 2021 | 7.5 | 79 | NO | YES |
CVE-2021-41174MEDIUM Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, | Nov 3, 2021 | 6.1 | 76 | NO | YES |
CVE-2018-15727CRITICAL Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an | Aug 29, 2018 | 9.8 | 76 | NO | YES |
CVE-2022-26148CRITICAL An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and a | Mar 21, 2022 | 9.8 | 73 | NO | YES |
CVE-2019-15043HIGH In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafan | Sep 3, 2019 | 7.5 | 68 | NO | YES |
Signals from CVEs in this vendor scope (133 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Grafana Labs.
Media articles that mention a CVE ID that affects a product developed by Grafana Labs — matched by CVE ID, not by vendor name.