The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.
github.com/grafana/grafana has critical vulnerabilities — do not use
Update to >= 0.0.0-20250521211231-e0ba4b480954 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | BIT-grafana-2023-6152 | Email Validation Bypass And Preventing Sign Up From Email's Owner | 10.3.3 |
| high | BIT-grafana-2020-12458 | Grafana information disclosure | 7.2.1 |
| high | BIT-grafana-2022-39307 | Grafana User enumeration via forget password | 8.5.15 |
| high | BIT-grafana-2025-3260 | Grafana vulnerable to authenticated users bypassing dashboard, folder permissions | 0.0.0-20250521183405-c7a690348df7 |
| medium | BIT-grafana-2026-27877 | Grafana public dashboards disclose all direct mode datasources | 1.9.2-0.20260325055210-3522153e07b4 |
| medium | BIT-grafana-2025-3415 | Grafana's insecure DingDing Alert integration exposes sensitive information | 1.9.2-0.20250514160932-04111e9f2afd |
| medium | BIT-grafana-2022-39324 | Grafana Spoofing originalUrl of snapshots | 8.5.16 |
| medium | CVE-2019-19499 | Grafana Arbitrary File Read | 6.4.4 |
| medium | BIT-grafana-2022-21713 | Grafana API IDOR | 8.3.5 |
| low | BIT-grafana-2024-10452 | Grafana org admin can delete pending invites in different org | — |
| high | BIT-grafana-2021-39226 | Authentication bypass for viewing and deletions of snapshots | 8.1.6 |
| medium | CVE-2018-18625 | Grafana XSS via adding a link in General feature | 6.0.0-beta1 |
| medium | BIT-grafana-2026-21724 | Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions | 1.9.2-0.20260323180334-daffe750de85 |
| medium | BIT-grafana-2020-13430 | Grafana XSS via the OpenTSDB datasource | 7.0.0 |
| medium | CVE-2019-13068 | Grafana Cross-site Scripting vulnerability | 6.2.5 |
| medium | CVE-2018-18624 | Grafana XSS via a column style | 7.0.0 |
| medium | BIT-grafana-2025-3454 | Grafana's datasource proxy API allows authorization checks to be bypassed | 0.0.0-20250424191517-1f707d16ed5d |
| medium | BIT-grafana-2020-12245 | Grafana XSS in header column rename | 6.7.3 |
| medium | CVE-2018-18623 | Grafana XSS in Dashboard Text Panel | 6.0.0-beta1 |
| low | BIT-grafana-2025-1088 | Grafana long dashboard title or panel name causes unresponsives | 0.0.0-20250521211231-e0ba4b480954 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/github.com/grafana/grafanaLast updated · 2019-08-19T14:38:14Z