Vulnerabilities > Grafana

DATE CVE VULNERABILITY TITLE RISK
2023-10-25 CVE-2023-3010 Cross-site Scripting vulnerability in Grafana Worldmap Panel
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana CWE-79
6.1
2023-10-17 CVE-2023-4399 Unspecified vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana
7.2
2023-10-16 CVE-2023-4457 Information Exposure Through an Error Message vulnerability in Grafana Google Sheets
Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is configured for the data source. This vulnerability was fixed in version 1.2.2.
network
low complexity
grafana CWE-209
7.5
2023-10-16 CVE-2023-4822 Unspecified vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana
7.2
2023-06-22 CVE-2023-3128 Authentication Bypass by Spoofing vulnerability in Grafana
Grafana is validating Azure AD accounts based on the email claim.
network
low complexity
grafana CWE-290
critical
9.8
2023-06-06 CVE-2023-2183 Missing Authorization vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana CWE-862
6.4
2023-06-06 CVE-2023-2801 Improper Synchronization vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
high complexity
grafana CWE-662
5.3
2023-04-26 CVE-2023-1387 Unspecified vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana
7.5
2023-03-23 CVE-2023-1410 Cross-site Scripting vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip.
network
low complexity
grafana CWE-79
4.8
2023-03-02 CVE-2023-22462 Cross-site Scripting vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana CWE-79
5.4