Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Kibana — Vulnerabilities & Security Advisories 107

All 107 CVE vulnerabilities found in Kibana, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Elastic Kibana, focusing on common weakness classifications. It collects a comprehensive list of reported security flaws affecting the Kibana dashboard and visualization platform, covering incidents from its initial release through the most recent updates in the current year. By consolidating these entries, the resource provides a unified view of the security landscape for this specific open-source data visualization tool. Users can track vendor advisories issued by Elastic to understand the timeline of discovery and remediation for critical issues. The page also allows readers to understand a weakness class by examining how specific vulnerabilities, such as cross-site scripting or authorization bypasses, have manifested in different versions of the software. Furthermore, users can look up a product's vulnerability history to assess the overall security posture and remediation practices over time. This structured approach helps security professionals, developers, and system administrators evaluate risks associated with their Kibana deployments. The data is organized to facilitate quick reference and deeper analysis of the types of flaws that have impacted the product, enabling informed decisions regarding patching and upgrade strategies. This aggregation serves as a historical record and a practical reference for maintaining the integrity of Kibana environments without requiring users to search multiple disparate sources for security information.

Vendor: Elastic

CVE IDTitleCVSSSeverityPublished
CVE-2025-68385 Kibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-79 7.2 High2025-12-18
CVE-2025-37732 Kibana Cross-site Scripting via the Integration Package Upload Functionality CWE-79 5.4 Medium2025-12-15
CVE-2025-37734 Kibana Origin Validation Error CWE-346 4.3 Medium2025-11-12
CVE-2025-37735 Elastic Defend 安全漏洞 CWE-281 7.0 High2025-11-06
CVE-2025-25017 Kibana Stored Cross-Site Scripting (XSS) CWE-79 8.2 High2025-10-10
CVE-2025-25018 Kibana Stored Cross-Site Scripting (XSS) CWE-79 8.7 High2025-10-10
CVE-2025-25009 Kibana Cross-Site Scripting (XSS) CWE-79 8.7 High2025-10-07
CVE-2025-37728 Kibana Insufficiently Protected Credentials in the CrowdStrike Connector CWE-522 5.4 Medium2025-10-07
CVE-2025-25010 Kibana privilege escalation via reporting_user role CWE-863 6.5 Medium2025-08-28
CVE-2025-25012 Kibana Open Redirect CWE-601 4.3 Medium2025-06-25
CVE-2024-43706 Kibana Improper Authorization CWE-285 7.6 High2025-06-10
CVE-2025-25014 Kibana arbitrary code execution via prototype pollution CWE-1321 9.1 Critical2025-05-06
CVE-2024-11390 Kibana Unrestricted Upload of File with Dangerous Type Can Lead to XSS CWE-434 5.4 Medium2025-05-01
CVE-2025-25016 Kibana Unrestricted Upload of File CWE-434 4.3 Medium2025-05-01
CVE-2024-12556 Kibana Prototype Pollution can lead to code injection CWE-1321 8.7 High2025-04-08
CVE-2024-52974 Elastic Kibana 资源管理错误漏洞 CWE-400 6.5 Medium2025-04-08
CVE-2025-25015 Kibana arbitrary code execution via prototype pollution CWE-1321 9.9 Critical2025-03-05
CVE-2024-43708 Elastic Kibana 安全漏洞 CWE-770 6.5 Medium2025-01-23
CVE-2024-52972 Kibana allocation of resources without limits or throttling leads to crash CWE-770 6.5 Medium2025-01-23
CVE-2024-43707 Kibana exposure of sensitive information to an unauthorized actor CWE-200 7.7 High2025-01-23
CVE-2024-43710 Kibana server-side request forgery CWE-918 4.3 Medium2025-01-23
CVE-2024-52973 Kibana allocation of resources without limits or throttling leads to crash CWE-770 6.5 Medium2025-01-21
CVE-2024-37285 Kibana arbitrary code execution via YAML deserialization CWE-502 9.1 Critical2024-11-14
CVE-2024-37288 Elastic Kibana 安全漏洞 CWE-502 9.9 Critical2024-09-09
CVE-2024-37287 Kibana arbitrary code execution via prototype pollution CWE-94 9.1 Critical2024-08-13
CVE-2024-37281 Kibana Denial of Service issue CWE-400 6.5 Medium2024-07-30
CVE-2024-23443 Elastic Kibana 安全漏洞 CWE-400 4.9 Medium2024-06-19
CVE-2024-23442 Kibana open redirect issue CWE-601 6.1 Medium2024-06-14
CVE-2024-37279 Kibana Broken Access Control issue 4.3 Medium2024-06-13
CVE-2024-23446 Kibana Broken Access Control issue CWE-284 6.5 Medium2024-02-07

All 107 known CVE vulnerabilities affecting Kibana with full Chinese analysis, references, and POCs where available.