In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14380.json"