Graylog records
22 published records for vendor graylog.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 59.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-532 Insertion of Sensitive Information into Log File2
- CWE-613 Insufficient Session Expiration2
- CWE-285 Improper Authorization2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-384 Session Fixation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2024-24824Proof of concept | graylog2-server vulnerable to instantiation of arbitrary classes triggered by API requestgraylog · graylog · CWE-284 | High8.8 | — | 34.7% | Feb 7, 2024 |
39Monitor | CVE-2021-37759No exploit | A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked sgraylog · graylog · CWE-532 | Critical9.8 | — | 1.3% | Jul 31, 2021 |
39Monitor | CVE-2021-37760No exploit | A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked sessiograylog · graylog · CWE-532 | Critical9.8 | — | 1.3% | Jul 31, 2021 |
37Monitor | CVE-2026-1435No exploit | Incorrect management of session invalidation vulnerability in Graylog Web Interfacegraylog · graylog · CWE-613 | Critical9.3 | — | 0.4% | Feb 18, 2026 |
35Monitor | CVE-2025-53106No exploit | Graylog vulnerable to privilege escalation through API tokensgraylog · graylog · CWE-285 | High8.8 | — | 0.6% | Jul 2, 2025 |
32Monitor | CVE-2020-15813No exploit | Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers.graylog · graylog · CWE-295 | High8.1 | — | 0.8% | Jul 17, 2020 |
28Monitor | CVE-2024-52506No exploit | Graylog can leak other users' reports via concurrent PDF report renderinggraylog · graylog · CWE-200 | High7.1 | — | 0.6% | Nov 18, 2024 |
28Monitor | CVE-2026-1436No exploit | Improper Access Control (IDOR) vulnerability in Graylog Web Interfacegraylog · graylog · CWE-639 | High7.1 | — | 0.2% | Feb 18, 2026 |
24Monitor | CVE-2018-14380No exploit | In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/Quegraylog · graylog · CWE-79 | Medium6.1 | — | 1.0% | Jul 18, 2018 |
24Monitor | CVE-2018-11650No exploit | Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.graylog · graylog · CWE-79 | Medium6.1 | — | 0.8% | Jun 1, 2018 |
24Monitor | CVE-2018-11651No exploit | Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, compograylog · graylog · CWE-79 | Medium6.1 | — | 0.8% | Jun 1, 2018 |
21Monitor | CVE-2023-41045No exploit | Insecure source port usage for DNS queries in Grayloggraylog · graylog · CWE-345 | Medium5.3 | — | 0.4% | Aug 31, 2023 |
21Monitor | CVE-2025-30373No exploit | Graylog Authenticated HTTP inputs do ingest message even if Authorization header is missing or has wrong valuegraylog · graylog · CWE-285 | Medium5.3 | — | 0.3% | Apr 7, 2025 |
21Monitor | CVE-2025-46827No exploit | Graylog Allows Session Takeover via Insufficient HTML Sanitizationgraylog · graylog · CWE-79 | Medium5.4 | — | 0.3% | May 7, 2025 |
21Monitor | CVE-2026-1437No exploit | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interfacegraylog · graylog · CWE-79 | Medium5.3 | — | 0.2% | Feb 18, 2026 |
21Monitor | CVE-2026-1441No exploit | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interfacegraylog · graylog · CWE-79 | Medium5.3 | — | 0.2% | Feb 18, 2026 |
21Monitor | CVE-2026-1440No exploit | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interfacegraylog · graylog · CWE-79 | Medium5.3 | — | 0.2% | Feb 18, 2026 |
21Monitor | CVE-2026-1438No exploit | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interfacegraylog · graylog · CWE-79 | Medium5.3 | — | 0.2% | Feb 18, 2026 |
21Monitor | CVE-2026-1439No exploit | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interfacegraylog · graylog · CWE-79 | Medium5.3 | — | 0.2% | Feb 18, 2026 |
17Monitor | CVE-2024-24823No exploit | graylog2-server Session Fixation vulnerability through cookie injectiongraylog · graylog · CWE-384 | Medium4.4 | — | 0.4% | Feb 7, 2024 |
15Monitor | CVE-2023-41044Proof of concept | Partial path traversal vulnerability in Support Bundle feature of Grayloggraylog · graylog · CWE-22 | Low3.8 | — | 0.7% | Aug 31, 2023 |
12Monitor | CVE-2023-41041No exploit | User session is still usable after logout in graylog2-servergraylog · graylog · CWE-613 | Low3.1 | — | 0.5% | Aug 30, 2023 |
- CVE-2024-2482445Plan
graylog2-server vulnerable to instantiation of arbitrary classes triggered by API request
HighCVSS 8.8Proof of conceptEPSS 35%graylog · graylogFeb 7, 2024
- CVE-2021-3775939Monitor
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked s
CriticalCVSS 9.8No exploitEPSS 1%graylog · graylogJul 31, 2021
- CVE-2021-3776039Monitor
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked sessio
CriticalCVSS 9.8No exploitEPSS 1%graylog · graylogJul 31, 2021
- CVE-2026-143537Monitor
Incorrect management of session invalidation vulnerability in Graylog Web Interface
CriticalCVSS 9.3No exploitEPSS 0%graylog · graylogFeb 18, 2026
- CVE-2025-5310635Monitor
Graylog vulnerable to privilege escalation through API tokens
HighCVSS 8.8No exploitEPSS 1%graylog · graylogJul 2, 2025
- CVE-2020-1581332Monitor
Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers.
HighCVSS 8.1No exploitEPSS 1%graylog · graylogJul 17, 2020
- CVE-2024-5250628Monitor
Graylog can leak other users' reports via concurrent PDF report rendering
HighCVSS 7.1No exploitEPSS 1%graylog · graylogNov 18, 2024
- CVE-2026-143628Monitor
Improper Access Control (IDOR) vulnerability in Graylog Web Interface
HighCVSS 7.1No exploitEPSS 0%graylog · graylogFeb 18, 2026
- CVE-2018-1438024Monitor
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/Que
MediumCVSS 6.1No exploitEPSS 1%graylog · graylogJul 18, 2018
- CVE-2018-1165024Monitor
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
MediumCVSS 6.1No exploitEPSS 1%graylog · graylogJun 1, 2018
- CVE-2018-1165124Monitor
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, compo
MediumCVSS 6.1No exploitEPSS 1%graylog · graylogJun 1, 2018
- CVE-2023-4104521Monitor
Insecure source port usage for DNS queries in Graylog
MediumCVSS 5.3No exploitEPSS 0%graylog · graylogAug 31, 2023
- CVE-2025-3037321Monitor
Graylog Authenticated HTTP inputs do ingest message even if Authorization header is missing or has wrong value
MediumCVSS 5.3No exploitEPSS 0%graylog · graylogApr 7, 2025
- CVE-2025-4682721Monitor
Graylog Allows Session Takeover via Insufficient HTML Sanitization
MediumCVSS 5.4No exploitEPSS 0%graylog · graylogMay 7, 2025
- CVE-2026-143721Monitor
Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface
MediumCVSS 5.3No exploitEPSS 0%graylog · graylogFeb 18, 2026
- CVE-2026-144121Monitor
Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface
MediumCVSS 5.3No exploitEPSS 0%graylog · graylogFeb 18, 2026
- CVE-2026-144021Monitor
Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface
MediumCVSS 5.3No exploitEPSS 0%graylog · graylogFeb 18, 2026
- CVE-2026-143821Monitor
Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface
MediumCVSS 5.3No exploitEPSS 0%graylog · graylogFeb 18, 2026
- CVE-2026-143921Monitor
Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface
MediumCVSS 5.3No exploitEPSS 0%graylog · graylogFeb 18, 2026
- CVE-2024-2482317Monitor
graylog2-server Session Fixation vulnerability through cookie injection
MediumCVSS 4.4No exploitEPSS 0%graylog · graylogFeb 7, 2024
- CVE-2023-4104415Monitor
Partial path traversal vulnerability in Support Bundle feature of Graylog
LowCVSS 3.8Proof of conceptEPSS 1%graylog · graylogAug 31, 2023
- CVE-2023-4104112Monitor
User session is still usable after logout in graylog2-server
LowCVSS 3.1No exploitEPSS 0%graylog · graylogAug 30, 2023