{"schema_version":1,"title":"github.com/grafana/grafana (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 47 vulnerabilities in github.com/grafana/grafana (Go): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-33381, was published on 13 May 2026.","url":"https://junglewise.ai/threats/technologies/github-com-grafana-grafana","json_url":"https://junglewise.ai/threats/technologies/github-com-grafana-grafana.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-grafana-grafana","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":47,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":5},"latest":[{"cve":"CVE-2026-33381","cvss":5.9,"epss":0.003,"slug":"cve-2026-33381-grafana-improper-access-control-in-service-account-token-minting","title":"Grafana improper access control in service account token minting","severity":"medium","exploited":false,"published_at":"2026-05-13T20:16:20.803+00:00","url":"https://junglewise.ai/threats/cve-2026-33381-grafana-improper-access-control-in-service-account-token-minting"},{"cve":"CVE-2026-33380","cvss":6.3,"epss":0.0032,"slug":"cve-2026-33380-grafana-arbitrary-file-read-in-sql-expressions","title":"Grafana arbitrary file read in SQL Expressions","severity":"medium","exploited":false,"published_at":"2026-05-13T20:16:20.697+00:00","url":"https://junglewise.ai/threats/cve-2026-33380-grafana-arbitrary-file-read-in-sql-expressions"},{"cve":"CVE-2026-21724","cvss":5.4,"epss":0.0026,"slug":"cve-2026-21724-grafana-oss-authorization-bypass-in-provisioning-contact-points","title":"Grafana OSS authorization bypass in provisioning contact points API","severity":"medium","exploited":false,"published_at":"2026-03-26T21:31:27+00:00","url":"https://junglewise.ai/threats/cve-2026-21724-grafana-oss-authorization-bypass-in-provisioning-contact-points"},{"cve":"CVE-2025-41117","cvss":6.8,"epss":0.0024,"slug":"cve-2025-41117-grafana-xss-in-explore-traces-view-via-jaeger-http-api","title":"Grafana XSS in Explore Traces view via Jaeger HTTP API","severity":"medium","exploited":false,"published_at":"2026-02-12T09:30:59+00:00","url":"https://junglewise.ai/threats/cve-2025-41117-grafana-xss-in-explore-traces-view-via-jaeger-http-api"},{"cve":"CVE-2025-41115","cvss":3.1,"epss":0.1691,"slug":"cve-2025-41115-grafana-incorrect-privilege-assignment-vulnerability","title":"GO-2025-4153 - Grafana Incorrect Privilege Assignment vulnerability in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2025-11-25T18:12:18+00:00","url":"https://junglewise.ai/threats/cve-2025-41115-grafana-incorrect-privilege-assignment-vulnerability"},{"cve":"CVE-2025-6023","cvss":3.1,"epss":0.4501,"slug":"cve-2025-6023-grafana-is-vulnerable-to-xss-attacks-through-open-redirects-and","title":"GO-2025-3817 - Grafana is vulnerable to XSS attacks through open redirects and path traversal in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2025-07-29T18:49:33+00:00","url":"https://junglewise.ai/threats/cve-2025-6023-grafana-is-vulnerable-to-xss-attacks-through-open-redirects-and"},{"cve":"CVE-2025-3415","cvss":3.1,"epss":0.0098,"slug":"cve-2025-3415-grafana-s-insecure-dingding-alert-integration-exposes-sensitive","title":"GO-2025-3814 - Grafana's insecure DingDing Alert integration exposes sensitive information in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2025-07-29T18:49:33+00:00","url":"https://junglewise.ai/threats/cve-2025-3415-grafana-s-insecure-dingding-alert-integration-exposes-sensitive"},{"cve":"CVE-2025-1088","cvss":3.1,"epss":0.0047,"slug":"cve-2025-1088-grafana-long-dashboard-title-or-panel-name-causes-unresponsives","title":"GO-2025-3766 - Grafana long dashboard title or panel name causes unresponsives in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2025-07-28T19:57:13+00:00","url":"https://junglewise.ai/threats/cve-2025-1088-grafana-long-dashboard-title-or-panel-name-causes-unresponsives"},{"cve":"CVE-2025-3454","cvss":3.1,"epss":0.0046,"slug":"cve-2025-3454-grafana-s-datasource-proxy-api-allows-authorization-checks-to-be","title":"GO-2025-3742 - Grafana's datasource proxy API allows authorization checks to be bypassed in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2025-06-09T18:14:36+00:00","url":"https://junglewise.ai/threats/cve-2025-3454-grafana-s-datasource-proxy-api-allows-authorization-checks-to-be"},{"cve":"CVE-2025-3260","cvss":3.1,"epss":0.0056,"slug":"cve-2025-3260-grafana-vulnerable-to-authenticated-users-bypassing-dashboard","title":"GO-2025-3740 - Grafana vulnerable to authenticated users bypassing dashboard, folder permissions in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2025-06-09T18:14:36+00:00","url":"https://junglewise.ai/threats/cve-2025-3260-grafana-vulnerable-to-authenticated-users-bypassing-dashboard"},{"cve":"CVE-2025-4123","cvss":3.1,"epss":0.9701,"slug":"cve-2025-4123-grafana-cross-site-scripting-xss-via-custom-loaded-frontend-plugin","title":"GO-2025-3704 - Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2025-05-27T20:47:04+00:00","url":"https://junglewise.ai/threats/cve-2025-4123-grafana-cross-site-scripting-xss-via-custom-loaded-frontend-plugin"},{"cve":"CVE-2024-11741","cvss":3.1,"epss":0.0041,"slug":"cve-2024-11741-grafana-alerting-victorops-integration-could-be-exposed-to-users","title":"GO-2025-3438 - Grafana Alerting VictorOps integration could be exposed to users with Viewer permission in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2025-02-04T22:06:11+00:00","url":"https://junglewise.ai/threats/cve-2024-11741-grafana-alerting-victorops-integration-could-be-exposed-to-users"},{"cve":"CVE-2024-10452","cvss":3.1,"epss":0.0049,"slug":"cve-2024-10452-grafana-org-admin-can-delete-pending-invites-in-different-org","title":"GO-2024-3240 - Grafana org admin can delete pending invites in different org in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-11-04T15:44:16+00:00","url":"https://junglewise.ai/threats/cve-2024-10452-grafana-org-admin-can-delete-pending-invites-in-different-org"},{"cve":"CVE-2024-9264","cvss":3.1,"epss":0.9486,"slug":"cve-2024-9264-grafana-command-injection-and-local-file-inclusion-via-sql","title":"GO-2024-3215 - Grafana Command Injection And Local File Inclusion Via Sql Expressions in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-10-28T15:20:02+00:00","url":"https://junglewise.ai/threats/cve-2024-9264-grafana-command-injection-and-local-file-inclusion-via-sql"},{"cve":"CVE-2024-6322","cvss":3.1,"epss":0.0031,"slug":"cve-2024-6322-grafana-plugin-data-sources-vulnerable-to-access-control-bypass","title":"GO-2024-3079 - Grafana plugin data sources vulnerable to access control bypass in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-08-22T20:03:04+00:00","url":"https://junglewise.ai/threats/cve-2024-6322-grafana-plugin-data-sources-vulnerable-to-access-control-bypass"},{"cve":"CVE-2018-15727","cvss":3,"epss":0.6428,"slug":"cve-2018-15727-grafana-authentication-bypass","title":"GO-2022-0707 - Grafana Authentication Bypass in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-08-21T15:21:45+00:00","url":"https://junglewise.ai/threats/cve-2018-15727-grafana-authentication-bypass"},{"cve":"CVE-2018-18623","cvss":3.1,"epss":0.0176,"slug":"cve-2018-18623-grafana-xss-in-dashboard-text-panel","title":"GO-2022-0342 - Grafana XSS in Dashboard Text Panel in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-08-21T14:30:29+00:00","url":"https://junglewise.ai/threats/cve-2018-18623-grafana-xss-in-dashboard-text-panel"},{"cve":"CVE-2020-12459","cvss":3.1,"epss":0.0032,"slug":"cve-2020-12459-grafana-world-readable-configuration-files","title":"GO-2024-2519 - Grafana world readable configuration files in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-07-02T19:23:51+00:00","url":"https://junglewise.ai/threats/cve-2020-12459-grafana-world-readable-configuration-files"},{"cve":"CVE-2020-12245","cvss":3.1,"epss":0.0196,"slug":"cve-2020-12245-grafana-xss-in-header-column-rename","title":"GO-2024-2517 - Grafana XSS in header column rename in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2020-12245-grafana-xss-in-header-column-rename"},{"cve":"CVE-2020-13430","cvss":3.1,"epss":0.0184,"slug":"cve-2020-13430-grafana-xss-via-the-opentsdb-datasource","title":"GO-2024-2515 - Grafana XSS via the OpenTSDB datasource in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2020-13430-grafana-xss-via-the-opentsdb-datasource"},{"cve":"CVE-2018-12099","cvss":3,"epss":0.0207,"slug":"cve-2018-12099-grafana-cross-site-scripting-xss","title":"GO-2024-2510 - Grafana Cross-site Scripting (XSS) in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2018-12099-grafana-cross-site-scripting-xss"},{"cve":"CVE-2020-11110","cvss":3.1,"epss":0.0962,"slug":"cve-2020-11110-grafana-stored-xss","title":"GO-2024-2523 - Grafana stored XSS in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2020-11110-grafana-stored-xss"},{"cve":"CVE-2018-18625","cvss":3.1,"epss":0.0119,"slug":"cve-2018-18625-grafana-xss-via-adding-a-link-in-general-feature","title":"GO-2024-2483 - Grafana XSS via adding a link in General feature in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2018-18625-grafana-xss-via-adding-a-link-in-general-feature"},{"cve":"CVE-2020-24303","cvss":3.1,"epss":0.0201,"slug":"cve-2020-24303-grafana-xss-via-a-query-alias-for-the-elasticsearch-datasource","title":"GO-2024-2520 - Grafana XSS via a query alias for the ElasticSearch datasource in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2020-24303-grafana-xss-via-a-query-alias-for-the-elasticsearch-datasource"},{"cve":"CVE-2018-18624","cvss":3.1,"epss":0.0141,"slug":"cve-2018-18624-grafana-xss-via-a-column-style","title":"GO-2024-2516 - Grafana XSS via a column style in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2018-18624-grafana-xss-via-a-column-style"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"}],"technology":{"hub":true,"name":"github.com/grafana/grafana (Go)","slug":"github-com-grafana-grafana","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://grafana.com/","repo_url":"https://github.com/grafana/grafana","description":"An open-source platform for monitoring and observability.","url":"https://junglewise.ai/threats/technologies/github-com-grafana-grafana"},"most_severe":[{"cve":"CVE-2025-41117","cvss":6.8,"epss":0.0024,"slug":"cve-2025-41117-grafana-xss-in-explore-traces-view-via-jaeger-http-api","title":"Grafana XSS in Explore Traces view via Jaeger HTTP API","severity":"medium","exploited":false,"published_at":"2026-02-12T09:30:59+00:00","url":"https://junglewise.ai/threats/cve-2025-41117-grafana-xss-in-explore-traces-view-via-jaeger-http-api"},{"cve":"CVE-2026-33380","cvss":6.3,"epss":0.0032,"slug":"cve-2026-33380-grafana-arbitrary-file-read-in-sql-expressions","title":"Grafana arbitrary file read in SQL Expressions","severity":"medium","exploited":false,"published_at":"2026-05-13T20:16:20.697+00:00","url":"https://junglewise.ai/threats/cve-2026-33380-grafana-arbitrary-file-read-in-sql-expressions"},{"cve":"CVE-2026-33381","cvss":5.9,"epss":0.003,"slug":"cve-2026-33381-grafana-improper-access-control-in-service-account-token-minting","title":"Grafana improper access control in service account token minting","severity":"medium","exploited":false,"published_at":"2026-05-13T20:16:20.803+00:00","url":"https://junglewise.ai/threats/cve-2026-33381-grafana-improper-access-control-in-service-account-token-minting"},{"cve":"CVE-2026-21724","cvss":5.4,"epss":0.0026,"slug":"cve-2026-21724-grafana-oss-authorization-bypass-in-provisioning-contact-points","title":"Grafana OSS authorization bypass in provisioning contact points API","severity":"medium","exploited":false,"published_at":"2026-03-26T21:31:27+00:00","url":"https://junglewise.ai/threats/cve-2026-21724-grafana-oss-authorization-bypass-in-provisioning-contact-points"},{"cve":"CVE-2025-4123","cvss":3.1,"epss":0.9701,"slug":"cve-2025-4123-grafana-cross-site-scripting-xss-via-custom-loaded-frontend-plugin","title":"GO-2025-3704 - Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2025-05-27T20:47:04+00:00","url":"https://junglewise.ai/threats/cve-2025-4123-grafana-cross-site-scripting-xss-via-custom-loaded-frontend-plugin"},{"cve":"CVE-2024-9264","cvss":3.1,"epss":0.9486,"slug":"cve-2024-9264-grafana-command-injection-and-local-file-inclusion-via-sql","title":"GO-2024-3215 - Grafana Command Injection And Local File Inclusion Via Sql Expressions in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-10-28T15:20:02+00:00","url":"https://junglewise.ai/threats/cve-2024-9264-grafana-command-injection-and-local-file-inclusion-via-sql"},{"cve":"CVE-2021-27358","cvss":3.1,"epss":0.8304,"slug":"cve-2021-27358-denial-of-service-in-grafana","title":"Denial of service in Grafana","severity":"low","exploited":false,"published_at":"2022-02-15T01:57:18+00:00","url":"https://junglewise.ai/threats/cve-2021-27358-denial-of-service-in-grafana"},{"cve":"CVE-2022-31097","cvss":3.1,"epss":0.686,"slug":"cve-2022-31097-grafana-stored-cross-site-scripting-in-unified-alerting","title":"GO-2024-2857 - Grafana Stored Cross-site Scripting in Unified Alerting in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2024-06-05T15:10:42+00:00","url":"https://junglewise.ai/threats/cve-2022-31097-grafana-stored-cross-site-scripting-in-unified-alerting"},{"cve":"CVE-2025-6023","cvss":3.1,"epss":0.4501,"slug":"cve-2025-6023-grafana-is-vulnerable-to-xss-attacks-through-open-redirects-and","title":"GO-2025-3817 - Grafana is vulnerable to XSS attacks through open redirects and path traversal in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2025-07-29T18:49:33+00:00","url":"https://junglewise.ai/threats/cve-2025-6023-grafana-is-vulnerable-to-xss-attacks-through-open-redirects-and"},{"cve":"CVE-2025-41115","cvss":3.1,"epss":0.1691,"slug":"cve-2025-41115-grafana-incorrect-privilege-assignment-vulnerability","title":"GO-2025-4153 - Grafana Incorrect Privilege Assignment vulnerability in github.com/grafana/grafana","severity":"low","exploited":false,"published_at":"2025-11-25T18:12:18+00:00","url":"https://junglewise.ai/threats/cve-2025-41115-grafana-incorrect-privilege-assignment-vulnerability"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}