grafana Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for grafana products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

6

In CISA KEV

2

Beyond CISA KEV

4

Sensor Observed

0

Virtual Patch Available

0

grafana KEVs Added by Year

Loading...

6 grafana KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2021-27358

The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API...

High Not in CISA 07 Jun 2026
CVE-2020-13379

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated...

High Not in CISA 04 Jun 2026
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers...

High Not in CISA 17 Jun 2025
CVE-2021-43798

Grafana path traversal

Confirmed In CISA 01 Jun 2026
CVE-2025-3415

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could...

High Not in CISA 17 Jul 2025
CVE-2021-39226

Snapshot authentication bypass in grafana

Confirmed In CISA 25 Aug 2022

Common Vulnerability Classes (CWE)

  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 1
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
  • CWE-287 — Improper Authentication 1
  • CWE-601 — URL Redirection to Untrusted Site ('Open Redirect') 1
  • CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 1
  • CWE-862 — Missing Authorization 1
  • CWE-918 — Server-Side Request Forgery (SSRF) 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology