16 Total CVEs
16 AI Analyzed
1 CISA KEV
6 Critical

Profile

6.3% ended up actively exploited 1 of 16 added to CISA KEV
38% rated critical (CVSS 9.0+) 6 critical, 10 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

16 CVEs in the last 12 months

Products

  • Grafana OSS2
  • Grafana IRM1
  • Loki Datasource Plugin1
  • Grafana Enterprise1
  • Snowflake Datasource1
  • Enterprise plugin1
  • config1
  • Grafana MCP Server1

9 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-16 of 16 CVEs
CVE-2026-9765
Analyzed
7.1
Grafana Grafana IRM

Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue

2026-07-26
CVE-2026-9029
Analyzed
7.3
Grafana Grafana OSS

The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug

2026-06-23
CVE-2026-42129
Analyzed
7.7
Grafana Loki Datasource Plugin

The Loki datasource plugin's callResource handler contains a path traversal vulnerability

2026-06-23
CVE-2026-42127
Analyzed
7.5
Grafana Grafana Enterprise

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory...

2026-06-23
CVE-2026-33382
Analyzed
7.5
Grafana Grafana OSS

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it

2026-07-12
CVE-2026-28381
Analyzed
9.6
Grafana Snowflake Datasource

The Grafana Snowflake Datasource allows authenticated users to read or write arbitrary files between the local Grafana server and the Snowflake host.

2026-06-23
CVE-2026-27880
Analyzed
7.5
Grafana Multiple Products

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes

2026-03-29
CVE-2026-27876
Analyzed
9.1
Grafana Enterprise plugin

A chained attack involving SQL Expressions and a Grafana Enterprise plugin enables remote arbitrary code execution (RCE) when the sqlExpressions featu...

2026-03-28
CVE-2026-21728
Analyzed
7.5
Grafana config

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strat...

2026-04-25
CVE-2026-21721
Analyzed
8.1
Grafana Multiple Products

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards

2026-01-27
CVE-2026-21720
Analyzed
7.5
Grafana Multiple Products

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image

2026-01-27
CVE-2026-15583
Analyzed
8.6
Grafana Grafana MCP Server

A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana servi...

2026-07-15
CVE-2025-41118
Analyzed
9.1
Grafana Multiple Products

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS...

2026-04-16
CVE-2025-41115
Analyzed
10
Grafana Multiple Products

SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by in...

2025-11-22
CVE-2025-11539
Analyzed
9.9
Grafana Multiple Products

Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/c...

2025-10-09
CVE-2021-43798
KEV Analyzed
9.5
Grafana Grafana

Grafana Path Traversal Vulnerability - Active in CISA KEV catalog.

2025-10-09