Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1167 articles · 105240 vulns · 38/41 feeds (7d)
← Back to list
EST
PRE-CVEEXPLOITED
grafana · grafana

Grafana Multiple Vulnerabilities - Cross-Site Scripting and Information Disclosure

72% confidence

Description

Multiple vulnerabilities in Grafana allow a remote authenticated attacker to manipulate files or cause a Denial-of-Service condition.

Affected Products

VendorProductVersions
grafanagrafana—
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-79, CWE-200
Published3/26/2026
Last enriched52m agov3
Tags
cross-site-scriptinginformation-disclosuregrafanadenial-of-serviceprivilege-escalation
Trending Score43
Source articles1
Independent1
Info Completeness7/14
Missing: cve_id, versions, cvss, epss, kev, patch, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: archived
Confidence: 7200%

Version History

v3
Last enriched 52m ago
v3Tier B52m ago

Updated description to include file manipulation and Denial-of-Service capabilities, and changed severity from HIGH to MEDIUM.

descriptionseverity
via BSI Advisories
v2Tier B4h ago

Updated severity to HIGH, marked exploit as available, and added new tags for denial-of-service and privilege escalation.

severityexploitAvailableactivelyExploitedtags
via BSI Advisories
v14h ago

Initial creation