VYPR

Misp

by Misp

Source repositories

CVEs (217)

  • CVE-2026-85238MedSep 3, 2026
    risk 0.37cvss 6.8epss 0.00

    MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without first rotating the session…

  • CVE-2024-58129MedMar 28, 2025
    risk 0.36cvss 5.5epss 0.00

    In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.

  • CVE-2024-58128MedMar 28, 2025
    risk 0.36cvss 5.5epss 0.00

    In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.

  • CVE-2021-27904MedMar 2, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.

  • CVE-2026-94393MedSep 21, 2026
    risk 0.35cvss —epss —

    When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report…

  • CVE-2026-86408MedSep 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive fields such as: * type…

  • CVE-2026-86347MedSep 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring template-management operations. The upload…

  • CVE-2026-85239MedSep 3, 2026
    risk 0.35cvss 6.5epss 0.00

    A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed semantic validation when the…

  • CVE-2026-10860MedJun 4, 2026
    risk 0.35cvss 6.5epss 0.00

    A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to missing parentheses in the delete condition, the expression was evaluated as ($validationError === null && POST) || DELETE,…

  • CVE-2026-9136MedMay 20, 2026
    risk 0.35cvss 6.5epss 0.00

    A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the record. Because the underlying framework treats a supplied primary key as an…

  • CVE-2025-67906MedDec 15, 2025
    risk 0.35cvss 5.4epss 0.00

    In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

  • CVE-2023-37307MedJun 30, 2023
    risk 0.35cvss 5.4epss 0.01

    In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.

  • CVE-2022-29531MedApr 20, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.

  • CVE-2022-29530MedApr 20, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.

  • CVE-2022-29529MedApr 20, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.

  • CVE-2021-37743MedJul 30, 2021
    risk 0.35cvss 5.4epss 0.01

    app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.

  • CVE-2021-37742MedJul 30, 2021
    risk 0.35cvss 5.4epss 0.01

    app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.

  • CVE-2021-37534MedJul 26, 2021
    risk 0.35cvss 5.4epss 0.01

    app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.

  • CVE-2019-19379MedNov 28, 2019
    risk 0.35cvss 5.3epss 0.01

    In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.

  • CVE-2019-16202MedSep 10, 2019
    risk 0.35cvss 6.5epss 0.01

    MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP…

Page 7 of 11