CVE-2026-69190
- EPSS 0.24%
- Veröffentlicht 21.09.2026 17:46:30
- Zuletzt bearbeitet 24.09.2026 21:17:43
Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareRequest that grant...
CVE-2026-92789
- EPSS 0.3%
- Veröffentlicht 16.09.2026 20:32:45
- Zuletzt bearbeitet 22.09.2026 20:53:07
Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoints that redi...
CVE-2026-55867
- EPSS 0.34%
- Veröffentlicht 28.08.2026 22:14:35
- Zuletzt bearbeitet 09.09.2026 21:09:13
Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog2/rest/resour...
CVE-2026-55841
- EPSS 0.36%
- Veröffentlicht 28.08.2026 22:11:08
- Zuletzt bearbeitet 09.09.2026 21:09:13
Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLForti...
- EPSS 0.3%
- Veröffentlicht 28.08.2026 18:08:22
- Zuletzt bearbeitet 09.09.2026 21:09:13
Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleServiceImpl.jav...
CVE-2026-1441
- EPSS 0.19%
- Veröffentlicht 18.02.2026 13:14:11
- Zuletzt bearbeitet 18.02.2026 20:20:16
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response withou...
CVE-2026-1440
- EPSS 0.19%
- Veröffentlicht 18.02.2026 13:13:51
- Zuletzt bearbeitet 18.02.2026 20:20:33
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response withou...
CVE-2026-1439
- EPSS 0.18%
- Veröffentlicht 18.02.2026 13:13:36
- Zuletzt bearbeitet 18.02.2026 20:20:50
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response withou...
CVE-2026-1438
- EPSS 0.18%
- Veröffentlicht 18.02.2026 13:13:23
- Zuletzt bearbeitet 18.02.2026 20:21:08
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response withou...
CVE-2026-1437
- EPSS 0.2%
- Veröffentlicht 18.02.2026 13:12:57
- Zuletzt bearbeitet 18.02.2026 20:21:24
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response withou...