Vulnerabilities > Graylog > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-24823 Session Fixation vulnerability in Graylog
Graylog is a free and open log management platform.
network
high complexity
graylog CWE-384
4.4
2023-08-31 CVE-2023-41045 Insufficient Verification of Data Authenticity vulnerability in Graylog
Graylog is a free and open log management platform.
network
low complexity
graylog CWE-345
5.3
2018-07-18 CVE-2018-14380 Cross-site Scripting vulnerability in Graylog
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
network
low complexity
graylog CWE-79
6.1
2018-06-01 CVE-2018-11651 Cross-site Scripting vulnerability in Graylog
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
network
low complexity
graylog CWE-79
6.1
2018-06-01 CVE-2018-11650 Cross-site Scripting vulnerability in Graylog
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
network
low complexity
graylog CWE-79
6.1