VYPR

Misp

by Misp

Source repositories

CVEs (217)

  • CVE-2026-56425HigJun 22, 2026
    risk 0.50cvss 8.8epss 0.00

    The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. The application used the PHP session identifier…

  • CVE-2026-56424HigJun 22, 2026
    risk 0.50cvss 8.8epss 0.01

    MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged authenticated user with the relevant feature…

  • CVE-2026-56423HigJun 22, 2026
    risk 0.50cvss 8.8epss 0.00

    MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of validating authorization for each selected object. For…

  • CVE-2026-54361HigJun 12, 2026
    risk 0.50cvss —epss 0.00

    MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Several controller actions accepted user-supplied fields that should have remained server-controlled, including record identifiers…

  • CVE-2026-94383HigSep 21, 2026
    risk 0.49cvss —epss —

    The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path components and a check for empty or dot values. A site administrator could specify a…

  • CVE-2026-85546HigSep 4, 2026
    risk 0.49cvss —epss 0.00

    MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, where the HTTP method validation intended to restrict these…

  • CVE-2023-37306HigJun 30, 2023
    risk 0.49cvss 7.5epss 0.01

    MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

  • CVE-2022-29534HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.

  • CVE-2021-31780HigApr 23, 2021
    risk 0.49cvss 7.5epss 0.01

    In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is…

  • CVE-2020-28043HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.01

    MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.

  • CVE-2020-25766HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.

  • CVE-2020-14969HigJun 22, 2020
    risk 0.49cvss 7.5epss 0.01

    app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.

  • CVE-2020-8893HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp.

  • CVE-2026-93296HigSep 17, 2026
    risk 0.48cvss —epss 0.00

    MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card and the server/feed preview card constructed donut chart legend labels by directly concatenating object name or category keys into an innerHTML string…

  • CVE-2026-90895HigSep 14, 2026
    risk 0.48cvss —epss 0.00

    Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web application in multiple security-sensitive…

  • CVE-2026-54360HigJun 12, 2026
    risk 0.48cvss —epss 0.00

    A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a user-supplied id field before saving the submitted data. In CakePHP, supplying a primary key in the save data can cause a…

  • CVE-2026-94401HigSep 21, 2026
    risk 0.47cvss —epss —

    MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was actually XML. Because of this, a user with…

  • CVE-2026-94374HigSep 21, 2026
    risk 0.47cvss —epss —

    MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves each one. Unlike the adjacent attribute…

  • CVE-2026-85538HigSep 4, 2026
    risk 0.47cvss —epss 0.00

    An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions. The affected attribute deletion paths relied on organization membership checks performed by…

  • CVE-2024-58130HigMar 28, 2025
    risk 0.47cvss 7.2epss 0.00

    In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.

Page 3 of 11