CVE-2025-1088
- EPSS 0.09%
- Veröffentlicht 18.06.2025 09:54:30
- Zuletzt bearbeitet 18.06.2025 13:46:52
In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.
- EPSS 0.01%
- Veröffentlicht 02.06.2025 10:34:09
- Zuletzt bearbeitet 02.06.2025 17:32:17
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager a...
CVE-2025-3260
- EPSS 0.02%
- Veröffentlicht 02.06.2025 10:15:21
- Zuletzt bearbeitet 02.06.2025 17:32:17
A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all...
CVE-2025-3580
- EPSS 0.02%
- Veröffentlicht 23.05.2025 13:44:45
- Zuletzt bearbeitet 23.05.2025 15:54:42
An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be e...
CVE-2025-4123
- EPSS 4.96%
- Veröffentlicht 22.05.2025 08:15:52
- Zuletzt bearbeitet 15.08.2025 19:37:01
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This...
CVE-2025-2703
- EPSS 0.02%
- Veröffentlicht 23.04.2025 11:36:02
- Zuletzt bearbeitet 10.06.2025 11:15:52
The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.
CVE-2024-11741
- EPSS 0.14%
- Veröffentlicht 31.01.2025 16:15:30
- Zuletzt bearbeitet 09.05.2025 20:15:38
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3, 11.2.6, 11.1...
CVE-2024-10452
- EPSS 0.22%
- Veröffentlicht 29.10.2024 16:15:04
- Zuletzt bearbeitet 08.11.2024 17:59:10
Organization admins can delete pending invites created in an organization they are not part of.
CVE-2024-9264
- EPSS 93.99%
- Veröffentlicht 18.10.2024 04:15:04
- Zuletzt bearbeitet 14.03.2025 10:15:15
The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusi...
CVE-2024-8118
- EPSS 0.07%
- Veröffentlicht 26.09.2024 19:15:07
- Zuletzt bearbeitet 30.09.2024 12:46:20
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.