Misp
by Misp
Source repositories
CVEs (217)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-86441 | Med | 0.21 | 4.3 | 0.00 | Sep 7, 2026 | Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_organisation_index_from_users. As a result, authenticated users without the… | ||
| CVE-2026-86418 | Med | 0.21 | 4.3 | 0.00 | Sep 7, 2026 | Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The affected endpoint returned fields including: -… | ||
| CVE-2026-86417 | Med | 0.21 | 4.3 | 0.00 | Sep 7, 2026 | Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering branch. As a result, the same authenticated user who saw… | ||
| CVE-2026-86342 | Med | 0.21 | 4.3 | 0.00 | Sep 7, 2026 | Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event correlations and associated… | ||
| CVE-2026-85226 | Med | 0.21 | 4.3 | 0.00 | Sep 3, 2026 | MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharing group, organization, or other access-control restrictions associated with the correlated… | ||
| CVE-2026-10864 | Med | 0.21 | 4.3 | 0.00 | Jun 4, 2026 | A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influence which fields were returned by the New Users and New Organisations widgets. In some cases, requesting a field set that became empty after validation or… | ||
| CVE-2026-10855 | Med | 0.21 | 4.3 | 0.00 | Jun 4, 2026 | An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a matching template already existed but did not verify that the importing user belonged to the organization… | ||
| CVE-2026-10854 | Med | 0.21 | 4.3 | 0.00 | Jun 4, 2026 | A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxies belonging to other organisations. The event template builder loaded all enabled galaxies without applying organisation or distribution-based access… | ||
| CVE-2026-67178 | Hig | 0.00 | — | 0.00 | Jul 28, 2026 | MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect: Redirect permanent / https://misp.example Apache’s Redirect directive appends any portion of the requested path that follows the matched… | ||
| CVE-2026-61474 | Med | 0.00 | — | 0.00 | Jul 9, 2026 | An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to add attributes to submit a sharing_group_id without triggering the corresponding sharing group authorization check, as long as the attribute distribution… | ||
| CVE-2026-60125 | Med | 0.00 | — | 0.00 | Jul 8, 2026 | MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not enforce the per-organisation module restriction checked by getEnabledModules(). As a result, an authenticated user from an organisation that was not allowed to… | ||
| CVE-2026-60124 | Med | 0.00 | — | 0.00 | Jul 8, 2026 | An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_standard format, the write… | ||
| CVE-2023-24028 | Cri | 0.00 | 9.8 | 0.01 | Jan 20, 2023 | In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function. | ||
| CVE-2023-24026 | Med | 0.00 | 6.1 | 0.00 | Jan 20, 2023 | In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload. | ||
| CVE-2018-11245 | Med | 0.00 | 6.1 | 0.01 | May 18, 2018 | app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes. | ||
| CVE-2018-8949 | Med | 0.00 | 4.3 | 0.01 | Mar 23, 2018 | An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attribute UUIDs but attribute IDs set) could overwrite an… | ||
| CVE-2018-8948 | Med | 0.00 | 6.1 | 0.01 | Mar 23, 2018 | In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module. |
- risk 0.21cvss 4.3epss 0.00
Affected versions of MISP contain inconsistent authorization checks across dashboard widgets that display organisation information. Several organisation-related widgets did not honor Security.hide_organisation_index_from_users. As a result, authenticated users without the…
- risk 0.21cvss 4.3epss 0.00
Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view. The affected endpoint returned fields including: -…
- risk 0.21cvss 4.3epss 0.00
Affected versions of MISP inconsistently enforced email-address visibility in DashboardsController::listTemplates(). The query always fetched User.email, while redaction happened only inside the non-REST rendering branch. As a result, the same authenticated user who saw…
- risk 0.21cvss 4.3epss 0.00
Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event correlations and associated…
- risk 0.21cvss 4.3epss 0.00
MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharing group, organization, or other access-control restrictions associated with the correlated…
- risk 0.21cvss 4.3epss 0.00
A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influence which fields were returned by the New Users and New Organisations widgets. In some cases, requesting a field set that became empty after validation or…
- risk 0.21cvss 4.3epss 0.00
An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a matching template already existed but did not verify that the importing user belonged to the organization…
- risk 0.21cvss 4.3epss 0.00
A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxies belonging to other organisations. The event template builder loaded all enabled galaxies without applying organisation or distribution-based access…
- risk 0.00cvss —epss 0.00
MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect: Redirect permanent / https://misp.example Apache’s Redirect directive appends any portion of the requested path that follows the matched…
- risk 0.00cvss —epss 0.00
An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to add attributes to submit a sharing_group_id without triggering the corresponding sharing group authorization check, as long as the attribute distribution…
- risk 0.00cvss —epss 0.00
MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not enforce the per-organisation module restriction checked by getEnabledModules(). As a result, an authenticated user from an organisation that was not allowed to…
- risk 0.00cvss —epss 0.00
An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not allowed to modify. When an import module returned results in the misp_standard format, the write…
- risk 0.00cvss 9.8epss 0.01
In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.
- risk 0.00cvss 6.1epss 0.00
In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.
- risk 0.00cvss 6.1epss 0.01
app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes.
- risk 0.00cvss 4.3epss 0.01
An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attribute UUIDs but attribute IDs set) could overwrite an…
- risk 0.00cvss 6.1epss 0.01
In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.
Page 11 of 11