VYPR

Misp

by Misp

Source repositories

CVEs (217)

  • CVE-2019-10254MedMar 28, 2019
    risk 0.40cvss 6.1epss 0.01

    In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability.

  • CVE-2018-11562MedMay 30, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter.

  • CVE-2017-15216MedOct 10, 2017
    risk 0.40cvss 6.1epss 0.01

    MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.

  • CVE-2017-13671MedAug 24, 2017
    risk 0.40cvss 6.1epss 0.01

    app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.

  • CVE-2017-7215MedMar 21, 2017
    risk 0.40cvss 6.1epss 0.02

    Cross site scripting in some view elements in the index filter tool in app/webroot/js/misp2.4.68.js and the organisation landing page in app/View/Organisations/ajax/landingpage.ctp of MISP before 2.4.69 allows remote attackers to inject arbitrary web script or HTML.

  • CVE-2026-94404HigSep 21, 2026
    risk 0.39cvss —epss —

    MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protection against forged requests. Because…

  • CVE-2026-91846HigSep 15, 2026
    risk 0.39cvss —epss 0.00

    Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselves only store UUIDs, while the collection…

  • CVE-2026-91825HigSep 15, 2026
    risk 0.39cvss —epss 0.00

    Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distribution = 4. If the attacker instead omitted…

  • CVE-2026-88915HigSep 10, 2026
    risk 0.39cvss —epss 0.00

    Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed that value into event creation without…

  • CVE-2026-86283HigSep 6, 2026
    risk 0.39cvss —epss 0.00

    MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs…

  • CVE-2026-54359HigJun 12, 2026
    risk 0.39cvss —epss 0.00

    MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests such as POST, PUT, or AJAX requests are not restricted based on the browser-provided Sec-Fetch-Site…

  • CVE-2026-95754MedSep 22, 2026
    risk 0.38cvss —epss —

    In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The query selected only User.password, User.totp, and…

  • CVE-2026-95679MedSep 22, 2026
    risk 0.38cvss —epss —

    MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build() library contains a logic error in its readFile guard condition (readFile && http || https), where PHP operator precedence causes the https branch to bypass…

  • CVE-2026-95667MedSep 22, 2026
    risk 0.38cvss —epss —

    The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_install.log and a named pipe (FIFO) at /var/log/misp_install.log.pipe to capture all installer output. The log captures highly sensitive data including the…

  • CVE-2026-95658MedSep 22, 2026
    risk 0.38cvss —epss —

    MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation for that action. Because…

  • CVE-2026-94379MedSep 21, 2026
    risk 0.38cvss —epss —

    The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PUT) before enforcing bruteforce protection,…

  • CVE-2026-92003MedSep 15, 2026
    risk 0.38cvss —epss 0.00

    Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model:  - API requests with no authentication key;  - requests supplying an API key with an…

  • CVE-2026-91819MedSep 15, 2026
    risk 0.38cvss —epss 0.00

    Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For override values outside the…

  • CVE-2020-8891MedFeb 12, 2020
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.

  • CVE-2020-8890MedFeb 12, 2020
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests.

Page 6 of 11