Graylog Web Interface是美国Graylog公司的一套Web界面。 Graylog Web Interface 2.2.3版本存在跨站脚本漏洞,该漏洞源于HTML输出缺少适当的清理和转义,可能导致通过端点/system/index_sets/注入和执行任意JavaScript代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Graylog | Graylog Web Interface | 2.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-1436 | Improper Access Control (IDOR) vulnerability in Graylog Web Interface | |
| CVE-2026-1440 | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface | |
| CVE-2026-1438 | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface | |
| CVE-2026-1439 | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface | |
| CVE-2026-1437 | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface | |
| CVE-2026-1435 | Incorrect management of session invalidation vulnerability in Graylog Web Interface |
No comments yet