Search CVE reports


Toggle filters

1 – 10 of 78 results


CVE-2025-6197

Medium priority
Needs evaluation

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana Not in release Not in release
Show less packages

CVE-2025-6023

Medium priority
Needs evaluation

An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana Not in release Not in release
Show less packages

CVE-2025-3415

Medium priority
Needs evaluation

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01,...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana Not in release Not in release
Show less packages

CVE-2025-1088

Medium priority
Needs evaluation

In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana Not in release Not in release
Show less packages

CVE-2025-3454

Medium priority
Needs evaluation

This vulnerability in Grafana’s datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana Not in release Not in release Not in release
Show less packages

CVE-2025-3260

Medium priority
Needs evaluation

A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: -...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana Not in release Not in release Not in release
Show less packages

CVE-2025-3580

Medium priority
Needs evaluation

An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana Not in release Not in release Not in release
Show less packages

CVE-2025-4123

Medium priority
Needs evaluation

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana Not in release Not in release Not in release
Show less packages

CVE-2024-11741

Medium priority
Needs evaluation

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1,...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana Not in release Not in release Not in release
Show less packages

CVE-2024-9476

Medium priority
Needs evaluation

A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration...

1 affected package

grafana

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
grafana Not in release Not in release Not in release
Show less packages