VYPR

Kibana

by Elastic

npm: kibana

Source repositories

CVEs (161)

  • CVE-2026-63141MedJul 21, 2026
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

  • CVE-2025-68387MedDec 18, 2025
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function…

  • CVE-2024-23442MedJun 14, 2024
    risk 0.40cvss 6.1epss 0.00

    An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

  • CVE-2022-38779MedFeb 22, 2023
    risk 0.40cvss 6.1epss 0.01

    An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

  • CVE-2021-22141MedNov 18, 2022
    risk 0.40cvss 6.1epss 0.01

    An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.

  • CVE-2022-23713MedJul 6, 2022
    risk 0.40cvss 6.1epss 0.01

    A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed in a victim’s browser.

  • CVE-2022-23710MedMar 3, 2022
    risk 0.40cvss 6.1epss 0.01

    A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow arbitrary JavaScript to be executed in a victim’s browser.

  • CVE-2020-27816MedDec 2, 2020
    risk 0.40cvss 6.1epss 0.01

    The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource.…

  • CVE-2018-3830MedSep 19, 2018
    risk 0.40cvss 6.1epss 0.02

    Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2018-3821MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    Kibana versions after 5.1.1 and before 5.6.7 and 6.1.3 had a cross-site scripting (XSS) vulnerability in the tag cloud visualization that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2018-3820MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    Kibana versions after 6.1.0 and before 6.1.3 had a cross-site scripting (XSS) vulnerability in labs visualizations that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2018-3819MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

  • CVE-2018-3818MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting (XSS) vulnerability via the colored fields formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2017-11482MedDec 8, 2017
    risk 0.40cvss 6.1epss 0.01

    The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

  • CVE-2017-11481MedDec 8, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2017-11479MedSep 29, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2017-8451MedJun 16, 2017
    risk 0.40cvss 6.1epss 0.01

    With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

  • CVE-2016-10366MedJun 16, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.

  • CVE-2016-10365MedJun 16, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.

  • CVE-2016-1000220MedJun 16, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.

Page 5 of 9