Grafana enterprise
This hub aggregates every CVE we track for Grafana enterprise, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
16
CVEs tracked
2
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM9HIGH4CRITICAL2LOW1
Monthly trend
0
0
0
0
0
0
0
1
0
1
0
0
0
0
1
0
0
0
0
0
0
1
1
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Grafana enterprise.
- CVE-2026-28378Cross-Organization Public Dashboard Deletion via Missing Org Isolation3.1
- CVE-2026-42127Pre-authentication denial of service in the public dashboard query endpoint7.5
- CVE-2025-41115Incorrect privilege assignment10.0
- CVE-2025-3454This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauth...5.0
- CVE-2025-2703The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.6.8
- CVE-2024-6322Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as...5.4
- CVE-2023-6152A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only ...5.4
- CVE-2023-4399Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance d...6.6
- CVE-2023-4822Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in...6.7
- CVE-2023-3128Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authenticatio...9.4
- CVE-2023-2183Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible...4.1
- CVE-2023-2801Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibili...7.5
- CVE-2023-1387Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use...4.2
- CVE-2023-1410Stored XSS in Graphite FunctionDescription tooltip6.2
- CVE-2023-0594Grafana is an open-source platform for monitoring and observability. Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the trace view visualization. The stored XSS vulnera...7.3
Product normalization is registry-driven with AI assist and human review. How it works