CVE-2018-14380: Graylog

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.

Affected products

  • Graylog Graylog: before 2.4.6 (fixed in 2.4.6)

Published 2018-07-18. Last modified 2026-06-17.