Vulnerabilities > Graylog > Graylog > 0.12.0

DATE CVE VULNERABILITY TITLE RISK
2023-08-31 CVE-2023-41045 Insufficient Verification of Data Authenticity vulnerability in Graylog
Graylog is a free and open log management platform.
network
low complexity
graylog CWE-345
5.3
2020-07-17 CVE-2020-15813 Improper Certificate Validation vulnerability in Graylog
Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers.
network
graylog CWE-295
6.8
2018-07-18 CVE-2018-14380 Cross-site Scripting vulnerability in Graylog
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
network
graylog CWE-79
4.3
2018-06-01 CVE-2018-11651 Cross-site Scripting vulnerability in Graylog
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
network
graylog CWE-79
4.3
2018-06-01 CVE-2018-11650 Cross-site Scripting vulnerability in Graylog
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
network
graylog CWE-79
4.3