Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Grafana Labs

First CVE: Jun 11, 2018Active for: 8 yearsTotal CVEs: 133
65.5
VTI Score
TOP TARGET

Grafana Labs maintains a widely deployed observability platform spanning dashboarding, monitoring agents, metrics storage, and log aggregation products that sit on the perimeter between trusted infrastructure and user-facing interfaces. Despite a focused product portfolio, the vendor's prominence in the landscape reflects the central role these tools play in visibility and alerting across enterprise environments. Vulnerabilities affecting the vendor skew toward moderate severity and frequently acquire public exploit code; the exposure recurs through web-application and access-control weakness classes including cross-site scripting, information disclosure, path traversal, and authorization flaws that are characteristic of services exposed to both internal and external networks. Defenders should prioritize patches for internet-facing instances and authentication-boundary services; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
133
Total CVEs
More Total CVEs than 99% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
1.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Grafana Labs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 11, 2018
8 years ago
Most Recent CVE
Jul 16, 2026
7 days ago

Self-Reporting Analysis

Of all the CVEs published by Grafana Labs as a CNA, 83.1% affect products that Grafana Labs develops as a vendor.

83.1%
16.9%
Self-reported: 69 (83.1%)
Third-party: 14 (16.9%)

Of all the CVEs published that affect products developed by Grafana Labs, 51.9% are self-published by Grafana Labs as a CNA.

51.9%
48.1%
Self-published: 69 (51.9%)
Other CNAs: 64 (48.1%)

Products(17 total)

Top CVEs

Signals from CVEs in this vendor scope (133 CVEs).

133 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-43798HIGH
Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal,
Dec 7, 20217.598YESYES
CVE-2021-39226HIGH
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by ac
Oct 5, 20217.397YESYES
CVE-2020-13379HIGH
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP re
Jun 3, 20208.290NOYES
CVE-2025-4123MEDIUM
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website tha
May 22, 20256.189NOYES
CVE-2024-9264HIGH
The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being pas
Oct 18, 20248.888NOYES
CVE-2021-27358HIGH
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configurat
Mar 18, 20217.579NOYES
CVE-2021-41174MEDIUM
Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page,
Nov 3, 20216.176NOYES
CVE-2018-15727CRITICAL
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an
Aug 29, 20189.876NOYES
CVE-2022-26148CRITICAL
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and a
Mar 21, 20229.873NOYES
CVE-2019-15043HIGH
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafan
Sep 3, 20197.568NOYES
View all 133 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products133 CVEs
49%
38%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (5.3%)
Network126 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low126 (94.7%)
High7 (5.3%)
Unknown0 (0.0%)
User Interaction
None101 (75.9%)
Unknown0 (0.0%)
Required32 (24.1%)
Privileges Required
Low64 (48.1%)
High15 (11.3%)
None54 (40.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (133 CVEs).

CISA KEV
2 CVEs
1.5% of CVEs· 99th percentile
Metasploit
2 CVEs
1.5% of CVEs· 97th percentile
Nuclei
10 CVEs
7.5% of CVEs· 96th percentile
ExploitDB
4 CVEs
3.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Grafana Labs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Grafana Labs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Grafana Labs's Products

View all 4 CNAs →

Top CWEs