Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Graylog

First CVE: Jun 1, 2018Active for: 8 yearsTotal CVEs: 22
28.2
VTI Score
Low

Graylog develops a centralized log management and analysis platform widely deployed in enterprise security operations and compliance environments, concentrating its vulnerability footprint in a single core product. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and they recur across predictable application-layer weakness classes: cross-site scripting, improper authorization, insufficient session management, and the inadvertent logging of sensitive data. These flaws reflect the dual exposure inherent to a web-facing data-aggregation service—the complexity of parsing and neutralizing untrusted log inputs while maintaining granular access controls across multi-tenant deployments. Defenders should treat Graylog advisories as a priority for internet-reachable infrastructure and review both access-control configurations and the scope of data flowing into the platform. Live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
3.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Graylog over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 1, 2018
8 years ago
Most Recent CVE
Feb 18, 2026
156 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-24824HIGH
Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP
Feb 7, 20248.841NONO
CVE-2026-1435CRITICAL
Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application genera
Feb 18, 20269.834NONO
CVE-2021-37759CRITICAL
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
Jul 31, 20219.831NONO
CVE-2021-37760CRITICAL
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).
Jul 31, 20219.830NONO
CVE-2025-53106HIGH
Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain elevated privileges by creating
Jul 2, 20258.825NONO
CVE-2026-1436MEDIUM
Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can access other user's profiles without
Feb 18, 20266.522NONO
CVE-2026-1441MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several
Feb 18, 20266.121NONO
CVE-2026-1439MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several
Feb 18, 20266.121NONO
CVE-2026-1438MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several
Feb 18, 20266.121NONO
CVE-2026-1437MEDIUM
Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several
Feb 18, 20266.121NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
9%
64%
14%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (86.4%)
High3 (13.6%)
Unknown0 (0.0%)
User Interaction
None12 (54.5%)
Unknown0 (0.0%)
Required10 (45.5%)
Privileges Required
Low7 (31.8%)
High1 (4.5%)
None14 (63.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Graylog.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Graylog — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Graylog's Products

View all 3 CNAs →

Top CWEs