VYPR
Vendor

Graylog

Products
2
CVEs
10
Across products
12
Status
Private

Products

2

Recent CVEs

10
  • CVE-2021-37760CriJul 31, 2021
    risk 0.64cvss 9.8epss 0.01

    A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).

  • CVE-2021-37759CriJul 31, 2021
    risk 0.64cvss 9.8epss 0.01

    A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).

  • CVE-2026-1441Feb 18, 2026
    risk 0.00cvss epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding,…

  • CVE-2026-1440Feb 18, 2026
    risk 0.00cvss epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding,…

  • CVE-2026-1439Feb 18, 2026
    risk 0.00cvss epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding,…

  • CVE-2026-1438Feb 18, 2026
    risk 0.00cvss epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding,…

  • CVE-2026-1437Feb 18, 2026
    risk 0.00cvss epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding,…

  • CVE-2026-1436Feb 18, 2026
    risk 0.00cvss epss 0.00

    Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can access other user's profiles without proper authorization checks. Exploiting this vulnerability allows valid users of the system to be…

  • CVE-2026-1435Feb 18, 2026
    risk 0.00cvss epss 0.00

    Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued…

  • CVE-2014-9217Dec 8, 2014
    risk 0.00cvss epss 0.02

    Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards.