Vulnerabilities > Grafana > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-04-30 CVE-2021-31231 Unspecified vulnerability in Grafana Enterprise Metrics
The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used.
local
low complexity
grafana
5.5
2021-03-22 CVE-2021-28147 Unspecified vulnerability in Grafana
The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue.
network
low complexity
grafana
6.5
2021-03-22 CVE-2021-28146 Incorrect Authorization vulnerability in Grafana
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue.
network
low complexity
grafana CWE-863
6.5
2020-10-28 CVE-2020-24303 Cross-site Scripting vulnerability in Grafana
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
network
low complexity
grafana CWE-79
6.1
2020-08-28 CVE-2019-19499 SQL Injection vulnerability in Grafana
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
network
low complexity
grafana CWE-89
6.5
2020-07-27 CVE-2020-11110 Cross-site Scripting vulnerability in multiple products
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.
network
low complexity
grafana netapp CWE-79
5.4
2020-06-02 CVE-2018-18625 Cross-site Scripting vulnerability in Grafana 5.3.1
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen.
network
low complexity
grafana CWE-79
6.1
2020-06-02 CVE-2018-18624 Cross-site Scripting vulnerability in Grafana 5.3.1
Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen.
network
low complexity
grafana CWE-79
6.1
2020-06-02 CVE-2018-18623 Cross-site Scripting vulnerability in Grafana 5.3.1
Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen.
network
low complexity
grafana CWE-79
6.1
2020-05-24 CVE-2020-13430 Cross-site Scripting vulnerability in Grafana
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
network
low complexity
grafana CWE-79
6.1