Vector
This hub aggregates every CVE we track for Vector, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
0
0
0
0
0
0
3
2024-102026-09
Latest CVEs
The 6 most recently published vulnerabilities affecting Vector.
- CVE-2026-77621Vector: Arbitrary file write in the file sink via templated path (path traversal).
- CVE-2026-77620Vector: Unauthenticated denial of service in the `logstash` source via nested compressed frames (stack exhaustion and decompression amplification).
- CVE-2026-77619Vector: Unauthenticated denial of service in the `logstash` source via unbounded memory allocation.
- CVE-2025-61657Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Vector. This vulnerability is associated with program files resourc...
- CVE-2025-6596Vector inserts portlet labels as HTML, allowing for stored XSS through system messages
- CVE-2023-30610AWS SDK for Rust will log AWS credentials when TRACE-level logging is enabled for request sending5.5
Product normalization is registry-driven with AI assist and human review. How it works