VYPR
Vendor

Graylog

Products
3
CVEs
27
Across products
36
Status
Private

Products

3

Recent CVEs

27
View all 27 CVEs →
  • CVE-2026-1435CriFeb 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued…

  • CVE-2021-37760CriJul 31, 2021
    risk 0.64cvss 9.8epss 0.01

    A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).

  • CVE-2021-37759CriJul 31, 2021
    risk 0.64cvss 9.8epss 0.01

    A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).

  • CVE-2024-24824HigFeb 7, 2024
    risk 0.53cvss 8.8epss 0.35

    Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. Graylog's cluster config system uses…

  • CVE-2020-15813HigJul 17, 2020
    risk 0.53cvss 8.1epss 0.01

    Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in LDAP. The connection configuration allows the usage of unencrypted, SSL- or TLS-secured connections. Unfortunately, the Graylog client code (in all…

  • CVE-2025-46827HigMay 7, 2025
    risk 0.52cvss 8.0epss 0.00

    Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtain user session cookies by submitting an HTML form as part of an Event Definition Remediation Step field. For this attack to succeed, the attacker needs a user…

  • CVE-2025-53106HigJul 2, 2025
    risk 0.50cvss 8.8epss 0.01

    Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain elevated privileges by creating and using API tokens for the local Administrator or any other user for whom the malicious user…

  • CVE-2026-1436MedFeb 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can access other user's profiles without proper authorization checks. Exploiting this vulnerability allows valid users of the system to be…

  • CVE-2024-52506MedNov 18, 2024
    risk 0.42cvss 6.5epss 0.01

    Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and scheduling of reports which contain dashboard widgets displaying individual log messages or metrics aggregated from fields of multiple log messages. This…

  • CVE-2026-1441MedFeb 18, 2026
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding,…

  • CVE-2026-1440MedFeb 18, 2026
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding,…

  • CVE-2026-1439MedFeb 18, 2026
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding,…

  • CVE-2026-1438MedFeb 18, 2026
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding,…

  • CVE-2026-1437MedFeb 18, 2026
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding,…

  • CVE-2018-14380MedJul 18, 2018
    risk 0.40cvss 6.1epss 0.01

    In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.

  • CVE-2018-11651MedJun 1, 2018
    risk 0.40cvss 6.1epss 0.01

    Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.

  • CVE-2018-11650MedJun 1, 2018
    risk 0.40cvss 6.1epss 0.01

    Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.

  • CVE-2026-92789MedSep 16, 2026
    risk 0.35cvss 6.5epss 0.00

    Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoints that redirect to internal services,…

  • CVE-2025-30373MedApr 7, 2025
    risk 0.35cvss 6.5epss 0.00

    Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing header or a wrong value…

  • CVE-2026-69190MedSep 21, 2026
    risk 0.34cvss 6.3epss 0.00

    Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareRequest that grants owner permissions to an…