CVE security advisories and vulnerability history for Grafana.
Grafana has 157 published CVE records since 2018, of which 2 are in CISA's Known Exploited Vulnerabilities catalog and 14 have a known public exploit. The average CVSS base score across scored CVEs is 6.6.
This page aggregates every publicly disclosed vulnerability (CVE) affecting Grafana products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.
A quick read on Grafana's vulnerability posture, as a share of its 157 published CVEs.
across 157 scored CVEs
75 of 157 scored
2 of 157 CVEs
14 of 157 CVEs
156 of 157 CVEs
How the CVSS severity of Grafana's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
2
2 of Grafana's CVEs are confirmed exploited in the wild.
Public exploits
14
14 of Grafana's CVEs have a known public exploit available.
The Grafana products with the most published CVEs. Follow any product to browse its versions and vulnerabilities.
The CWE weakness categories most often found in Grafana CVEs. Follow any weakness for its full explanation.
The CVE Numbering Authorities that publish Grafana CVE records.
How many Grafana CVEs were published each year.
The most recently disclosed vulnerabilities affecting Grafana.
Browse vulnerabilities for other tracked vendors.
Common questions about Grafana vulnerabilities.
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Monitor new Grafana vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.
Track new Grafana CVEs as they are disclosed and get AI-written analysis and remediation guidance.
Monitor Grafana CVEs