Known vulnerabilities in Grafana - page 3
Vendor:
Grafana Labs
Software:
Grafana
Software CPE:
cpe:2.3:a:grafana_labs:grafana:*:*:*:*:*:*:*:*
Website:
https://github.com/grafana
Total vulnerabilities:
118
Public exploits:
11
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
13.2.0
13.1.4
13.0.7
12.4.9
12.3.11
13.1.3
13.0.6
12.4.8
13.1.2
12.4.7
12.3.10
13.0.5
13.1.1
13.0.4
12.4.6
12.3.9
13.1.0
13.0.3
12.4.5
12.3.8
12.2.10
11.6.16
12.4.4
12.3.7
12.2.9
11.6.15
13.0.2
13.0.1+security-01
12.4.3+security-02
12.3.6+security-04
12.2.8+security-04
11.6.14+security-04
13.0.1
13.0.0
12.4.3
12.4.2
12.3.6
12.3.6+security-01
12.2.8
12.2.8+security-01
12.1.10
12.1.10+security-01
11.6.14
11.6.14+security-01
12.3.5
12.2.7
12.1.9
11.6.13
12.4.1
12.4.0
12.3.4
12.2.6
12.1.8
11.6.12
12.3.3
12.2.5
12.1.7
12.0.10
12.3.2+security-01
12.2.4+security-01
12.1.6+security-01
11.6.10+security-01
11.6.11
12.3.1+security-01
12.2.3+security-01
12.2.1+security-01
12.1.5+security-01
12.1.3+security-01
12.0.8+security-01
12.0.6+security-01
11.6.9+security-01
11.3.0+security-01
12.3.2
12.2.4
12.1.6
12.0.9
11.6.10
12.3.1
12.2.3
12.1.5
12.0.8
11.6.9
12.3.0
12.2.2
12.1.4
12.0.7
11.6.8
12.2.1
12.1.3
12.0.6
11.6.7
11.5.10
12.2.0
12.1.2
12.0.5
11.6.6
11.5.9
12.1.1
12.0.4
11.6.5
11.5.8
11.4.8
12.0.3
12.1.0
11.6.4
11.5.7
11.4.7
11.3.9
12.0.1+security-01
11.6.2+security-01
11.5.5+security-01
11.4.5+security-01
11.3.7+security-01
11.2.10+security-01
10.4.19+security-01
11.3.8+security-01
11.4.6+security-01
11.5.6+security-01
11.6.3+security-01
12.0.2+security-01
12.0.2
11.6.3
11.5.6
11.4.6
11.3.8
11.6.0+security-01
11.5.3+security-01
11.4.3+security-01
11.3.5+security-01
11.2.8+security-01
10.4.17+security-01
10.4.19
12.0.1
11.6.2
11.5.5
11.4.5
11.3.7
11.2.10
10.4.18+security-01
11.2.9+security-01
11.3.6+security-01
11.4.4+security-01
11.5.4+security-01
11.6.1+security-01
12.0.0+security-01
12.0.0
11.6.1
11.5.4
11.4.4
11.3.6
11.2.9
10.4.18
11.6.0
11.5.3
11.4.3
11.3.5
11.2.8
11.1.13
10.4.17
11.5.2
11.4.2
11.3.4
11.2.7
11.1.12
10.4.16
11.5.1
11.0.11
11.5.0
11.4.1
11.3.3
11.2.6
11.1.11
11.0.10
10.4.15
11.4.0
11.3.2
11.2.5
11.1.10
11.0.9
10.4.14
11.3.1
11.2.4
11.1.9
11.0.8
10.4.13
10.4.12
11.3.0
11.2.3
11.1.8
11.0.7
10.4.11
10.3.12
11.2.2+security-01
11.1.7+security-01
11.0.6+security-01
11.2.1+security-01
11.1.6+security-01
11.0.5+security-01
11.2.2
11.1.7
11.0.6
10.4.10
10.3.11
11.2.1
11.1.6
11.0.5
10.4.9
10.3.10
11.1.5
11.0.4
10.4.8
11.2.0
10.3.9
11.1.4
11.0.3
10.4.7
11.1.3
11.1.1
9.5.21
11.1.2
11.0.2
10.4.6
10.3.8
10.2.9
10.3.7
10.2.8
9.5.20
10.4.5
11.1.0
11.0.1
10.4.4
10.1.10
9.5.19
10.4.3
10.3.6
10.2.7
11.0.0
10.4.2
10.2.6
10.1.9
10.0.13
9.5.18
10.4.1
10.3.5
10.3.4
10.2.5
10.1.8
10.0.12
10.4.0
9.5.17
10.2.4
10.3.3
10.1.7
10.0.11
9.5.16
10.3.1
10.3.0
10.1.6
10.0.10
9.5.15
10.2.3
10.2.2
1.0.0
9.5.14
10.2.1
10.2.0
10.1.5
10.0.9
9.5.13
9.4.17
10.1.4
10.0.8
9.5.12
10.1.2
10.0.6
9.5.10
9.4.15
10.0.5
9.5.9
9.4.14
10.1.1
10.1.0
10.0.4
9.5.8
10.0.3
9.5.7
10.0.2
9.5.6
10.0.1
9.4.13
9.5.5
10.0.0
9.3.16
9.2.20
8.5.27
9.5.3
9.4.12
9.3.15
9.2.19
8.5.26
9.5.2
9.4.10
9.3.14
9.2.18
8.5.24
9.5.1
9.4.9
9.3.13
9.2.17
9.5.0
9.2.15
8.5.22
9.4.7
9.3.11
9.4.0
9.4.3
9.4.2
9.3.8
9.2.13
8.5.21
9.4.1
8.5.16
9.3.6
9.3.4
8.5.20
9.2.10
9.3.2
9.2.8
9.3.1
9.3.0
9.2.7
9.2.6
9.2.5
9.2.4
8.5.15
9.2.3
9.2.2
9.2.1
9.2.0
9.1.8
8.5.14
9.1.7
7.5.17
9.1.6
9.0.9
8.5.13
9.1.5
9.1.4
9.1.3
9.1.2
9.0.8
8.5.11
8.4.11
8.3.11
9.1.1
9.1.0
9.0.7
8.5.10
9.0.6
9.0.5
9.0.4
9.0.3
8.3.10
8.5.9
8.4.10
9.0.2
9.0.1
8.5.6
9.0.0
8.5.5
8.5.4
7.5.16
8.5.3
8.5.2
8.5.1
8.5.0
8.4.7
8.4.6
8.4.5
8.4.4
8.4.3
8.3.7
8.4.2
8.4.1
8.4.0
8.3.6
8.3.5
7.5.15
8.3.4
7.5.13
8.3.3
8.3.2
7.5.12
8.2.7
8.1.8
8.3.1
8.0.7
8.2.6
8.3.0
8.2.5
8.2.4
8.2.3
8.2.2
8.2.1
8.2.0
8.1.7
7.5.11
8.1.6
8.1.5
8.1.4
8.1.3
8.1.2
8.1.1
8.1.0
7.5.10
8.0.6
8.0.5
8.0.4
7.5.9
8.0.3
7.5.8
8.0.2
8.0.1
8.0.0
7.5.7
7.5.6
7.5.5
7.5.4
7.5.3
7.5.0
7.5.1
7.5.2
6.7.6
7.3.10
7.4.5
7.4.3
7.4.2
7.4.1
7.4.0
7.3.7
6.7.5
7.2.3
7.3.6
7.3.5
7.3.4
7.3.3
7.3.2
7.3.1
7.3.0
7.2.2
7.2.1
7.2.0
7.1.4
7.1.5
7.1.3
7.1.2
7.1.1
7.1.0
7.0.6
7.0.5
7.0.4
7.0.3
6.7.4
7.0.2
7.0.1
7.0.0
6.7.3
6.7.2
6.7.1
6.7.0
6.6.2
6.6.1
6.6.0
6.5.3
6.5.2
6.5
6.5.1
6.5.0
6.4.5
6.3.7
6.4.4
6.4.3
6.4.2
6.4.1
6.4.0
6.3.6
6.3.5
2.0.0
6.3.4
6.3.3
6.3.2
6.3.1
6.3.0
6.2.5
6.2.4
6.2.3
6.2.2
6.2.1
6.2.0
6.1.6
6.1.4
6.1.3
6.1.2
6.1.1
6.1.0
6.0.2
6.0.1
6.0.0
5.4.5
5.4.4
5.4.3
5.4.2
5.4.1
5.4.0
5.3.4
5.2.5
1.0.3
1.0.2
1.0.1
1.0
5.2.4
5.3.3
5.3.2
5.3.1
5.3.0-beta3
5.3.0-beta2
5.3.0-beta1
5.3.0
4.6.5
5.2.3
5.2.2
5.2.1
5.2.0-beta3
5.2.0-beta2
5.2.0-beta1
5.1.0-beta1
5.0.0-beta5
5.0.0-beta4
5.0.0-beta3
5.0.0-beta2
5.0.0-beta1
4.6.4
4.6.0-beta3
4.6.0-beta2
4.6.0-beta1
4.5.0-beta1
4.3.0-beta1
4.2.0-beta1
4.1.0-beta1
4.0.0-beta2
4.0.0-beta1
3.1.1
3.1.0-beta1
3.1.0
3.0.4
3.0.3
3.0.2
3.0.1
3.0.0-beta7
3.0.0-beta6
3.0-beta5
3.0-beta4
3.0-beta3
3.0-beta2
3.0-beta1
2.6.0-beta1
2.6.0
2.5.0
2.1.3
2.1.2
2.1.1
2.1.0
2.0.2
2.0.1
2.0.0-beta3
2.0.0-beta1
1.9.1
1.9.0-rc1
1.9.0
1.8.1
1.8.0-rc1
1.8.0
1.7.0-rc1
1.7.0
1.6.1
1.6.0
1.5.4
1.5.3
1.5.2
1.5.1
1.5.0
1.4.0
1.3.0
1.2.0
1.1.0
1.0.4
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.3.1
4.3.2
4.4.0
4.4.1
4.4.2
4.4.3
4.5.0
4.5.1
4.5.2
4.6.0
4.6.1
4.6.2
4.6.3
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.2.0
Vulnerabilities (118)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU111266 - Improper input validation CVE-2025-1088 |
CWE-20 | Low | 11.6.2 | 18.06.2025 |
SB2025061829 |
||
| #VU110174 - Improper Authorization CVE-2025-3260 |
CWE-285 | Medium | 11.6.1+security-01 | 03.06.2025 |
SB2025060322 |
||
| #VU110090 - Improper Authorization CVE-2025-3454 |
CWE-285 | Medium | 10.4.17+security-01, 11.2.8+security-01, 11.3.5+security-01, 11.4.3+security-01, 11.5.3+security-01, 11.6.0+security-01 | 03.06.2025 |
SB2025060314 |
||
| #VU109851 - Improper Access Control CVE-2025-3580 |
CWE-284 | Low | 10.4.19, 11.2.10, 11.3.7, 11.4.5, 11.5.5, 11.6.2, 12.0.1 | 27.05.2025 |
SB2025052748 |
||
| #VU109656 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-4123 |
CWE-79 | Low | 10.4.18+security-01, 11.2.9+security-01, 11.3.6+security-01, 11.4.4+security-01, 11.5.4+security-01, 11.6.1+security-01, 12.0.0+security-01 | 22.05.2025 |
SB2025052230 SB2025052236 SB2025052237 and 7 more |
||
| #VU103503 - Exposure of sensitive information to an unauthorized actor CVE-2024-11741 |
CWE-200 | Medium | 10.4.15, 11.0.11, 11.1.11, 11.2.6, 11.3.3, 11.4.1, 11.5.0 | 03.02.2025 |
SB2025020329 SB2025022148 SB2025022149 and 1 more |
||
| #VU99259 - Improper Access Control CVE-2024-8118 |
CWE-284 | Low | 10.4.11, 11.0.7, 11.1.8 | 22.10.2024 |
SB20241022375 SB2025021467 SB2025021742 and 1 more |
||
| #VU98806 - Improper Control of Filename for Include/Require Statement in PHP Program CVE-2024-9264 |
CWE-98 | Medium | 11.0.5+security-01, 11.0.6+security-01, 11.1.6+security-01, 11.1.7+security-01, 11.2.1+security-01, 11.2.2+security-01 | 18.10.2024 |
SB2024101803 |
||
| #VU96048 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-6837 |
CWE-79 | Medium | 10.4.7, 11.0.3, 11.1.4 | 15.08.2024 |
SB2024081534 SB2025021467 SB2025021742 and 1 more |
||
| #VU92186 - Permissions, Privileges, and Access Controls CVE-2023-4822 |
CWE-264 | Low | 9.4.17, 9.5.12, 10.0.8, 10.1.4 | 17.06.2024 |
SB2023101664 SB2024061802 SB2024071933 |
||
| #VU89210 - Incorrect Authorization CVE-2023-6152 |
CWE-863 | Low | 9.5.16, 10.0.11, 10.1.7, 10.2.4, 10.3.3 | 07.05.2024 |
SB2024050715 SB2024050717 SB2024050718 and 8 more |
||
| #VU87845 - Improper Authorization CVE-2024-1313 |
CWE-285 | Medium | 9.5.18, 10.0.13, 10.1.9, 10.2.6, 10.3.5 | 27.03.2024 |
SB2024032711 SB2024043089 SB2024050720 and 10 more |
||
| #VU87328 - Improper Access Control CVE-2024-1442 |
CWE-284 | Medium | 9.5.7, 10.0.12, 10.1.8, 10.2.5, 10.3.4 | 11.03.2024 |
SB2024031121 SB2024050135 SB2024081506 and 2 more |
||
| #VU78470 - Missing Authorization CVE-2023-2183 |
CWE-862 | Low | 8.5.26, 9.2.19, 9.3.15, 9.4.12, 9.5.3 | 20.07.2023 |
SB20230720110 SB20230720114 SB20230720115 and 9 more |
||
| #VU77652 - Improper Authentication CVE-2023-3128 |
CWE-287 | High | 9.2.20, 9.3.16 | 22.06.2023 |
SB2023062281 SB2023071336 SB20230720114 and 15 more |
||
| #VU77623 - Improper Synchronization CVE-2023-2801 |
CWE-662 | Medium | 9.4.12, 9.5.3 | 22.06.2023 |
SB2023062244 SB20230720114 SB20230720115 and 8 more |
||
| #VU77620 - Exposure of sensitive information to an unauthorized actor CVE-2023-1387 |
CWE-200 | Medium | 9.2.17, 9.3.13, 9.4.9 | 22.06.2023 |
SB2023062227 SB2023062230 SB2023062231 and 7 more |
||
| #VU75360 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-1410 |
CWE-79 | Low | 8.5.22, 9.2.15, 9.3.11 | 19.04.2023 |
SB2023041950 SB2023041951 SB2023041952 and 11 more |
||
| #VU75359 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-0594 |
CWE-79 | Low | 8.5.21, 9.2.13, 9.3.8 | 19.04.2023 |
SB2023041949 SB2023041951 SB2023041952 and 6 more |
||
| #VU75358 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-0507 |
CWE-79 | Low | 8.5.21, 9.2.13, 9.3.8 | 19.04.2023 |
SB2023041949 SB2023041951 SB2023041952 and 6 more |
Showing elements 41 - 60 out of 118