Home/Product/logpoint siem
Product

logpoint siem

24 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-35548
< 7.9.0
An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix 7.9.0.0).
8.5HIGH
CVE-2025-66361
< 7.7.0
An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period duri
6.5MEDIUM
CVE-2025-66360
< 7.7.0
An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint intern
8.8HIGH
CVE-2025-66359
< 7.7.0
An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multiple componen
8.5HIGH
CVE-2024-56087
< 7.5.0
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard
5.9MEDIUM
CVE-2024-56086
< 7.5.0
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed
7.1HIGH
CVE-2024-56085
< 7.5.0
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard
5.9MEDIUM
CVE-2024-56084
< 5.7.0
An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Unive
7.1HIGH
CVE-2024-48954
< 7.5.0
An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user l
6.4MEDIUM
CVE-2024-48953
< 7.5.0
An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules
7.5HIGH
CVE-2024-48952
< 7.5.0
An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR A
6.4MEDIUM
CVE-2024-48951
< 7.5.0
An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API To
7.5HIGH
CVE-2024-48950
< 7.5.0
An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthentic
7.5HIGH
CVE-2024-36383
< 6.0.3
An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the state field
5.3MEDIUM
CVE-2024-33860
< 7.4.0
An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within
6.5MEDIUM
CVE-2024-33859
< 7.4.0
An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting Field" Web
6.1MEDIUM
CVE-2024-33858
< 7.4.0
An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The
5.3MEDIUM
CVE-2024-33857
< 7.4.0
An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker wi
9.6CRITICAL
CVE-2024-33856
< 7.4.0
An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response ti
5.3MEDIUM
CVE-2024-30176
< 7.4.0
In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets.
5.3MEDIUM
CVE-2022-48685
>= 7.1.0 and < 7.1.2
An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by all users a
7.7HIGH
CVE-2022-48684
< 7.1.1
An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jin
8.4HIGH
CVE-2024-29865
< 7.1.0
Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.
5.4MEDIUM
CVE-2023-49950
>= 6.10.0 and < 7.3.0
The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when us
5.4MEDIUM
threatengine.sh