Home/Product/graylog
Product

graylog

22 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-1441
all versions
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper
6.1MEDIUM
CVE-2026-1440
all versions
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper
6.1MEDIUM
CVE-2026-1439
all versions
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper
6.1MEDIUM
CVE-2026-1438
all versions
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper
6.1MEDIUM
CVE-2026-1437
all versions
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper
6.1MEDIUM
CVE-2026-1436
all versions
Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authentic
6.5MEDIUM
CVE-2026-1435
all versions
Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session inv
9.8CRITICAL
CVE-2025-53106
>= 6.2.0 and < 6.2.4
Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Gray
8.8HIGH
CVE-2025-46827
< 6.0.14
Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtain user ses
8.0HIGH
CVE-2025-30373
>= 6.1.0 and < 6.1.9
Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified heade
6.5MEDIUM
CVE-2024-52506
>= 6.1.0 and < 6.1.2
Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and scheduling of r
6.5MEDIUM
CVE-2024-24824
>= 2.0.0 and < 5.1.11
Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary cl
8.8HIGH
CVE-2024-24823
>= 4.3.0 and < 5.1.11
Graylog is a free and open log management platform. Starting in version 4.3.0 and prior to versions 5.1.11 and 5.2.4, reauthentica
5.7MEDIUM
CVE-2023-41045
< 5.0.9
Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Graylog bind
3.7LOW
CVE-2023-41044
>= 5.1.0 and < 5.1.3
Graylog is a free and open log management platform. A partial path traversal vulnerability exists in Graylog's Support Bundle fe
3.3LOW
CVE-2023-41041
>= 1.0.0 and < 5.0.9
Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged out, a use
2.6LOW
CVE-2021-37760
>= 2.1.1 and < 4.1.2
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the lea
9.8CRITICAL
CVE-2021-37759
>= 0.20.0 and < 4.1.2
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of th
9.8CRITICAL
CVE-2020-15813
< 3.3.3
Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in
8.1HIGH
CVE-2018-14380
< 2.4.6
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/
6.1MEDIUM
CVE-2018-11651
< 2.4.4
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.
6.1MEDIUM
CVE-2018-11650
< 2.4.4
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.
6.1MEDIUM
threatengine.sh