Broken record, but "has a CVSS score of 10.0" is literally meaningless. In fact, over the last couple years, I've come to take vulnerabilities with very high CVSS scores less seriously. Remember, Heartbleed was a "7.5".
I'd think logging things like query parameters is extremely common.
I could even do without "crit".
It is different than the cvss rating.