Known vulnerabilities in Grafana - page 2
Vendor:
Grafana Labs
Software:
Grafana
Software CPE:
cpe:2.3:a:grafana_labs:grafana:*:*:*:*:*:*:*:*
Website:
https://github.com/grafana
Total vulnerabilities:
118
Public exploits:
11
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
13.2.0
13.1.4
13.0.7
12.4.9
12.3.11
13.1.3
13.0.6
12.4.8
13.1.2
12.4.7
12.3.10
13.0.5
13.1.1
13.0.4
12.4.6
12.3.9
13.1.0
13.0.3
12.4.5
12.3.8
12.2.10
11.6.16
12.4.4
12.3.7
12.2.9
11.6.15
13.0.2
13.0.1+security-01
12.4.3+security-02
12.3.6+security-04
12.2.8+security-04
11.6.14+security-04
13.0.1
13.0.0
12.4.3
12.4.2
12.3.6
12.3.6+security-01
12.2.8
12.2.8+security-01
12.1.10
12.1.10+security-01
11.6.14
11.6.14+security-01
12.3.5
12.2.7
12.1.9
11.6.13
12.4.1
12.4.0
12.3.4
12.2.6
12.1.8
11.6.12
12.3.3
12.2.5
12.1.7
12.0.10
12.3.2+security-01
12.2.4+security-01
12.1.6+security-01
11.6.10+security-01
11.6.11
12.3.1+security-01
12.2.3+security-01
12.2.1+security-01
12.1.5+security-01
12.1.3+security-01
12.0.8+security-01
12.0.6+security-01
11.6.9+security-01
11.3.0+security-01
12.3.2
12.2.4
12.1.6
12.0.9
11.6.10
12.3.1
12.2.3
12.1.5
12.0.8
11.6.9
12.3.0
12.2.2
12.1.4
12.0.7
11.6.8
12.2.1
12.1.3
12.0.6
11.6.7
11.5.10
12.2.0
12.1.2
12.0.5
11.6.6
11.5.9
12.1.1
12.0.4
11.6.5
11.5.8
11.4.8
12.0.3
12.1.0
11.6.4
11.5.7
11.4.7
11.3.9
12.0.1+security-01
11.6.2+security-01
11.5.5+security-01
11.4.5+security-01
11.3.7+security-01
11.2.10+security-01
10.4.19+security-01
11.3.8+security-01
11.4.6+security-01
11.5.6+security-01
11.6.3+security-01
12.0.2+security-01
12.0.2
11.6.3
11.5.6
11.4.6
11.3.8
11.6.0+security-01
11.5.3+security-01
11.4.3+security-01
11.3.5+security-01
11.2.8+security-01
10.4.17+security-01
10.4.19
12.0.1
11.6.2
11.5.5
11.4.5
11.3.7
11.2.10
10.4.18+security-01
11.2.9+security-01
11.3.6+security-01
11.4.4+security-01
11.5.4+security-01
11.6.1+security-01
12.0.0+security-01
12.0.0
11.6.1
11.5.4
11.4.4
11.3.6
11.2.9
10.4.18
11.6.0
11.5.3
11.4.3
11.3.5
11.2.8
11.1.13
10.4.17
11.5.2
11.4.2
11.3.4
11.2.7
11.1.12
10.4.16
11.5.1
11.0.11
11.5.0
11.4.1
11.3.3
11.2.6
11.1.11
11.0.10
10.4.15
11.4.0
11.3.2
11.2.5
11.1.10
11.0.9
10.4.14
11.3.1
11.2.4
11.1.9
11.0.8
10.4.13
10.4.12
11.3.0
11.2.3
11.1.8
11.0.7
10.4.11
10.3.12
11.2.2+security-01
11.1.7+security-01
11.0.6+security-01
11.2.1+security-01
11.1.6+security-01
11.0.5+security-01
11.2.2
11.1.7
11.0.6
10.4.10
10.3.11
11.2.1
11.1.6
11.0.5
10.4.9
10.3.10
11.1.5
11.0.4
10.4.8
11.2.0
10.3.9
11.1.4
11.0.3
10.4.7
11.1.3
11.1.1
9.5.21
11.1.2
11.0.2
10.4.6
10.3.8
10.2.9
10.3.7
10.2.8
9.5.20
10.4.5
11.1.0
11.0.1
10.4.4
10.1.10
9.5.19
10.4.3
10.3.6
10.2.7
11.0.0
10.4.2
10.2.6
10.1.9
10.0.13
9.5.18
10.4.1
10.3.5
10.3.4
10.2.5
10.1.8
10.0.12
10.4.0
9.5.17
10.2.4
10.3.3
10.1.7
10.0.11
9.5.16
10.3.1
10.3.0
10.1.6
10.0.10
9.5.15
10.2.3
10.2.2
1.0.0
9.5.14
10.2.1
10.2.0
10.1.5
10.0.9
9.5.13
9.4.17
10.1.4
10.0.8
9.5.12
10.1.2
10.0.6
9.5.10
9.4.15
10.0.5
9.5.9
9.4.14
10.1.1
10.1.0
10.0.4
9.5.8
10.0.3
9.5.7
10.0.2
9.5.6
10.0.1
9.4.13
9.5.5
10.0.0
9.3.16
9.2.20
8.5.27
9.5.3
9.4.12
9.3.15
9.2.19
8.5.26
9.5.2
9.4.10
9.3.14
9.2.18
8.5.24
9.5.1
9.4.9
9.3.13
9.2.17
9.5.0
9.2.15
8.5.22
9.4.7
9.3.11
9.4.0
9.4.3
9.4.2
9.3.8
9.2.13
8.5.21
9.4.1
8.5.16
9.3.6
9.3.4
8.5.20
9.2.10
9.3.2
9.2.8
9.3.1
9.3.0
9.2.7
9.2.6
9.2.5
9.2.4
8.5.15
9.2.3
9.2.2
9.2.1
9.2.0
9.1.8
8.5.14
9.1.7
7.5.17
9.1.6
9.0.9
8.5.13
9.1.5
9.1.4
9.1.3
9.1.2
9.0.8
8.5.11
8.4.11
8.3.11
9.1.1
9.1.0
9.0.7
8.5.10
9.0.6
9.0.5
9.0.4
9.0.3
8.3.10
8.5.9
8.4.10
9.0.2
9.0.1
8.5.6
9.0.0
8.5.5
8.5.4
7.5.16
8.5.3
8.5.2
8.5.1
8.5.0
8.4.7
8.4.6
8.4.5
8.4.4
8.4.3
8.3.7
8.4.2
8.4.1
8.4.0
8.3.6
8.3.5
7.5.15
8.3.4
7.5.13
8.3.3
8.3.2
7.5.12
8.2.7
8.1.8
8.3.1
8.0.7
8.2.6
8.3.0
8.2.5
8.2.4
8.2.3
8.2.2
8.2.1
8.2.0
8.1.7
7.5.11
8.1.6
8.1.5
8.1.4
8.1.3
8.1.2
8.1.1
8.1.0
7.5.10
8.0.6
8.0.5
8.0.4
7.5.9
8.0.3
7.5.8
8.0.2
8.0.1
8.0.0
7.5.7
7.5.6
7.5.5
7.5.4
7.5.3
7.5.0
7.5.1
7.5.2
6.7.6
7.3.10
7.4.5
7.4.3
7.4.2
7.4.1
7.4.0
7.3.7
6.7.5
7.2.3
7.3.6
7.3.5
7.3.4
7.3.3
7.3.2
7.3.1
7.3.0
7.2.2
7.2.1
7.2.0
7.1.4
7.1.5
7.1.3
7.1.2
7.1.1
7.1.0
7.0.6
7.0.5
7.0.4
7.0.3
6.7.4
7.0.2
7.0.1
7.0.0
6.7.3
6.7.2
6.7.1
6.7.0
6.6.2
6.6.1
6.6.0
6.5.3
6.5.2
6.5
6.5.1
6.5.0
6.4.5
6.3.7
6.4.4
6.4.3
6.4.2
6.4.1
6.4.0
6.3.6
6.3.5
2.0.0
6.3.4
6.3.3
6.3.2
6.3.1
6.3.0
6.2.5
6.2.4
6.2.3
6.2.2
6.2.1
6.2.0
6.1.6
6.1.4
6.1.3
6.1.2
6.1.1
6.1.0
6.0.2
6.0.1
6.0.0
5.4.5
5.4.4
5.4.3
5.4.2
5.4.1
5.4.0
5.3.4
5.2.5
1.0.3
1.0.2
1.0.1
1.0
5.2.4
5.3.3
5.3.2
5.3.1
5.3.0-beta3
5.3.0-beta2
5.3.0-beta1
5.3.0
4.6.5
5.2.3
5.2.2
5.2.1
5.2.0-beta3
5.2.0-beta2
5.2.0-beta1
5.1.0-beta1
5.0.0-beta5
5.0.0-beta4
5.0.0-beta3
5.0.0-beta2
5.0.0-beta1
4.6.4
4.6.0-beta3
4.6.0-beta2
4.6.0-beta1
4.5.0-beta1
4.3.0-beta1
4.2.0-beta1
4.1.0-beta1
4.0.0-beta2
4.0.0-beta1
3.1.1
3.1.0-beta1
3.1.0
3.0.4
3.0.3
3.0.2
3.0.1
3.0.0-beta7
3.0.0-beta6
3.0-beta5
3.0-beta4
3.0-beta3
3.0-beta2
3.0-beta1
2.6.0-beta1
2.6.0
2.5.0
2.1.3
2.1.2
2.1.1
2.1.0
2.0.2
2.0.1
2.0.0-beta3
2.0.0-beta1
1.9.1
1.9.0-rc1
1.9.0
1.8.1
1.8.0-rc1
1.8.0
1.7.0-rc1
1.7.0
1.6.1
1.6.0
1.5.4
1.5.3
1.5.2
1.5.1
1.5.0
1.4.0
1.3.0
1.2.0
1.1.0
1.0.4
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
Vulnerabilities (118)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU131641 - Improper Access Control CVE-2026-33381 |
CWE-284 | Low | 11.6.14+security-04, 12.2.8+security-04, 12.3.6+security-04, 12.4.3+security-02, 13.0.1+security-01 | 18.05.2026 |
SB2026051824 |
||
| #VU131640 - Improper Access Control CVE-2026-33380 |
CWE-284 | Low | 11.6.14+security-04, 12.2.8+security-04, 12.3.6+security-04, 12.4.3+security-02, 13.0.1+security-01 | 18.05.2026 |
SB2026051824 |
||
| #VU126254 - Improper Access Control CVE-2025-12141 |
CWE-284 | Low | 12.3.1 | 15.04.2026 |
SB20260415176 |
||
| #VU124711 - Exposure of sensitive information to an unauthorized actor CVE-2026-27877 |
CWE-200 | Low | 11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2 | 31.03.2026 |
SB2026033194 SB2026042431 SB2026042902 and 2 more |
||
| #VU124710 - Improper input validation CVE-2026-33375 |
CWE-20 | Low | 11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2 | 31.03.2026 |
SB2026033194 SB2026060464 |
||
| #VU124709 - Improper Authorization CVE-2026-21724 |
CWE-285 | Low | 11.6.14, 12.1.10, 12.2.8, 12.3.6 | 31.03.2026 |
SB2026033194 SB2026060464 |
||
| #VU124708 - Improper input validation CVE-2026-28375 |
CWE-20 | Low | 11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2 | 31.03.2026 |
SB2026033194 SB2026060464 |
||
| #VU124707 - Resource exhaustion CVE-2026-27880 |
CWE-400 | Medium | 12.1.10, 12.2.8, 12.3.6, 12.4.2 | 31.03.2026 |
SB2026033194 |
||
| #VU124706 - Uncontrolled Memory Allocation CVE-2026-27879 |
CWE-789 | Low | 11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2 | 31.03.2026 |
SB2026033194 SB2026060464 |
||
| #VU124705 - Improper input validation CVE-2026-27876 |
CWE-20 | Low | 11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2 | 31.03.2026 |
SB2026033194 SB2026060464 |
||
| #VU123252 - Improper Authorization CVE-2026-21725 |
CWE-285 | Low | 12.4.1 | 25.02.2026 |
SB2026022533 |
||
| #VU122757 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-41117 |
CWE-79 | Low | 12.2.4+security-01, 12.3.2+security-01 | 12.02.2026 |
SB2026021238 |
||
| #VU122756 - Improper Access Control CVE-2026-21722 |
CWE-284 | Low | 11.6.10+security-01, 12.1.6+security-01, 12.2.4+security-01, 12.3.2+security-01 | 12.02.2026 |
SB2026021238 SB20260325198 SB2026040631 and 1 more |
||
| #VU122265 - Improper Access Control CVE-2026-21727 |
CWE-284 | Low | 11.6.11, 12.0.9, 12.1.6, 12.2.4, 12.3.2 | 03.02.2026 |
SB2026020361 |
||
| #VU122160 - Resource Management Errors CVE-2026-21720 |
CWE-399 | Medium | 11.6.9+security-01, 12.0.8+security-01, 12.1.5+security-01, 12.2.3+security-01, 12.3.1+security-01 | 30.01.2026 |
SB2026013061 SB20260325198 SB2026040631 |
||
| #VU122159 - Improper Privilege Management CVE-2026-21721 |
CWE-269 | Low | 11.6.9+security-01, 12.0.8+security-01, 12.1.5+security-01, 12.2.3+security-01, 12.3.1+security-01 | 30.01.2026 |
SB2026013061 SB2026022335 SB2026030249 and 4 more |
||
| #VU113609 - Authorization Bypass Through User-Controlled Key CVE-2024-10452 |
CWE-639 | Low | - | 04.08.2025 |
SB2025080425 SB2025080504 |
||
| #VU113081 - Exposure of sensitive information to an unauthorized actor CVE-2025-3415 |
CWE-200 | Medium | 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01, 12.0.1+security-01 | 21.07.2025 |
SB2025072113 SB2025112453 SB2025112454 and 3 more |
||
| #VU113080 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2025-6197 |
CWE-601 | Low | 11.3.8+security-01, 11.4.6+security-01, 11.5.6+security-01, 11.6.3+security-01, 12.0.2+security-01 | 21.07.2025 |
SB2025072114 SB2025112453 SB2025112454 |
||
| #VU113079 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2025-6023 |
CWE-601 | Medium | 11.3.8+security-01, 11.4.6+security-01, 11.5.6+security-01, 11.6.3+security-01, 12.0.2+security-01 | 21.07.2025 |
SB2025072114 SB2025112453 SB2025112454 |
Showing elements 21 - 40 out of 118