Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
Maven/org.graylog2:graylog2-server — 11 CVEs · VulnScope
pkg:Maven/
org.graylog2:graylog2-server
11 total CVEs
HIGH
2
MEDIUM
5
LOW
3
✅ Check your installed version
Check
All known vulnerabilities
HIGH
8.8
CVE-2024-24824
Graylog vulnerable to instantiation of arbitrary classes triggered by API request
>= 2.0.0, < 5.1.11
HIGH
8.0
CVE-2025-46827
Graylog Allows Session Takeover via Insufficient HTML Sanitization
from 0, < 6.0.14
MEDIUM
6.5
CVE-2025-30373
Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value
>= 6.1.0, < 6.1.9
MEDIUM
6.1
Cross-site Scripting in Graylog
from 0, < 2.4.4
MEDIUM
6.1
Cross-site Scripting in Graylog Server
from 0, < 2.4.4
MEDIUM
6.1
Cross-site Scripting in Graylog Server
from 0, < 2.4.6
MEDIUM
5.7
Graylog session fixation vulnerability through cookie injection
>= 4.3.0, < 5.1.11
LOW
3.7
Graylog vulnerable to insecure source port usage for DNS queries
>= 5.1.0, < 5.1.3
LOW
3.3
Graylog server has partial path traversal vulnerability in Support Bundle feature
>= 5.1.0, < 5.1.3
LOW
2.6
Graylog user session is still usable after logout
>= 1.0, < 5.0.9
—
Graylog vulnerable to privilege escalation through API tokens
>= 6.2.0, < 6.2.4
CVE-2018-11651
CVE-2018-11650
CVE-2018-14380
CVE-2024-24823
CVE-2023-41045
CVE-2023-41044
CVE-2023-41041
CVE-2025-53106