Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Kibana — Vulnerabilities & Security Advisories 154

All 154 CVE vulnerabilities found in Kibana, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumeration (CWE) vulnerabilities associated with the Kibana software product, developed by Elastic. It aggregates known security weaknesses that have been documented for this specific visualization and log management platform, providing a structured view of its historical security posture. The content collected here spans from the product’s initial releases through to the most recent updates, ensuring a comprehensive timeline of discovered flaws and their subsequent mitigations. By browsing this aggregation, users can effectively track vendor advisories issued by Elastic regarding specific security patches, understand the characteristics and potential impacts of distinct weakness classes such as buffer overflows or insecure defaults, and look up the detailed vulnerability history of Kibana to assess risk exposure over time. This resource serves as a centralized reference for security analysts, developers, and system administrators to evaluate the cumulative security landscape of the software without needing to search through disparate documentation sources individually. The focus remains strictly on factual data aggregation, presenting the evolution of identified weaknesses to facilitate informed decision-making regarding upgrade paths and configuration hardening. Readers are encouraged to review the chronological listings to identify patterns in vulnerability disclosure and remediation efforts, thereby gaining a clearer understanding of the long-term stability and security practices employed by the product maintainers. This approach allows for a thorough examination of how the software has addressed various security challenges across different versions, supporting proactive security management strategies within organizational environments that rely on Kibana for data analysis and monitoring.

Vendor: Elastic

CVE IDTitleCVSSSeverityPublished
CVE-2025-25016 Kibana Unrestricted Upload of File CWE-434 4.3 Medium2025-05-01
CVE-2024-12556 Kibana Prototype Pollution can lead to code injection CWE-1321 8.7 High2025-04-08
CVE-2024-52974 Elastic Kibana 资源管理错误漏洞 CWE-400 6.5 Medium2025-04-08
CVE-2025-25015 Kibana arbitrary code execution via prototype pollution CWE-1321 9.9 Critical2025-03-05
CVE-2024-43708 Elastic Kibana 安全漏洞 CWE-770 6.5 Medium2025-01-23
CVE-2024-52972 Kibana allocation of resources without limits or throttling leads to crash CWE-770 6.5 Medium2025-01-23
CVE-2024-43707 Kibana exposure of sensitive information to an unauthorized actor CWE-200 7.7 High2025-01-23
CVE-2024-43710 Kibana server-side request forgery CWE-918 4.3 Medium2025-01-23
CVE-2024-52973 Kibana allocation of resources without limits or throttling leads to crash CWE-770 6.5 Medium2025-01-21
CVE-2024-37285 Kibana arbitrary code execution via YAML deserialization CWE-502 9.1 Critical2024-11-14
CVE-2024-37288 Elastic Kibana 安全漏洞 CWE-502 9.9 Critical2024-09-09
CVE-2024-37287 Kibana arbitrary code execution via prototype pollution CWE-94 9.1 Critical2024-08-13
CVE-2024-37281 Kibana Denial of Service issue CWE-400 6.5 Medium2024-07-30
CVE-2024-23443 Elastic Kibana 安全漏洞 CWE-400 4.9 Medium2024-06-19
CVE-2024-23442 Kibana open redirect issue CWE-601 6.1 Medium2024-06-14
CVE-2024-37279 Kibana Broken Access Control issue 4.3 Medium2024-06-13
CVE-2024-23446 Kibana Broken Access Control issue CWE-284 6.5 Medium2024-02-07
CVE-2023-46675 Kibana Insertion of Sensitive Information into Log File CWE-532 8.0 High2023-12-13
CVE-2023-46671 Kibana Insertion of Sensitive Information into Log File CWE-532 8.0 High2023-12-13
CVE-2021-22142 Kibana Reporting vulnerabilities CWE-1104 6.6 Medium2023-11-22
CVE-2021-22151 Kibana path traversal issue CWE-22 3.1 Low2023-11-22
CVE-2021-22150 Kibana code execution issue CWE-94 6.6 Medium2023-11-22
CVE-2023-31422 Kibana Insertion of Sensitive Information into Log File CWE-532 9.0 Critical2023-10-26
CVE-2023-31415 Elastic Kibana 代码注入漏洞 CWE-94 9.9 -2023-05-04
CVE-2023-31414 Elastic Kibana 代码注入漏洞 CWE-94 9.1 -2023-05-04
CVE-2022-38779 Elastic Kibana 输入验证错误漏洞 CWE-601 6.1 -2023-02-21
CVE-2022-38778 Kibana 输入验证错误漏洞 CWE-20 6.5 -2023-02-08
CVE-2021-22141 Elastic Kibana 输入验证错误漏洞 CWE-601 6.1 -2022-11-18
CVE-2021-37936 Elastic Kibana 跨站脚本漏洞 CWE-79 6.1 -2022-11-18
CVE-2022-23713 Vega 跨站脚本漏洞 CWE-79 6.1 -2022-07-06

All 154 known CVE vulnerabilities affecting Kibana with full Chinese analysis, references, and POCs where available.