Misp
by Misp
Source repositories
CVEs (217)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-85238 | Med | 0.37 | 6.8 | 0.00 | Sep 3, 2026 | MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without first rotating the session… | ||
| CVE-2024-58129 | Med | 0.36 | 5.5 | 0.00 | Mar 28, 2025 | In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page. | ||
| CVE-2024-58128 | Med | 0.36 | 5.5 | 0.00 | Mar 28, 2025 | In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link. | ||
| CVE-2021-27904 | Med | 0.36 | 5.5 | 0.00 | Mar 2, 2021 | An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors. | ||
| CVE-2026-94393 | Med | 0.35 | — | — | Sep 21, 2026 | When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report… | ||
| CVE-2026-86408 | Med | 0.35 | 6.5 | 0.00 | Sep 7, 2026 | Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive fields such as: * type… | ||
| CVE-2026-86347 | Med | 0.35 | 6.5 | 0.00 | Sep 7, 2026 | Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring template-management operations. The upload… | ||
| CVE-2026-85239 | Med | 0.35 | 6.5 | 0.00 | Sep 3, 2026 | A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed semantic validation when the… | ||
| CVE-2026-10860 | Med | 0.35 | 6.5 | 0.00 | Jun 4, 2026 | A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to missing parentheses in the delete condition, the expression was evaluated as ($validationError === null && POST) || DELETE,… | ||
| CVE-2026-9136 | Med | 0.35 | 6.5 | 0.00 | May 20, 2026 | A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the record. Because the underlying framework treats a supplied primary key as an… | ||
| CVE-2025-67906 | Med | 0.35 | 5.4 | 0.00 | Dec 15, 2025 | In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path. | ||
| CVE-2023-37307 | Med | 0.35 | 5.4 | 0.01 | Jun 30, 2023 | In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts. | ||
| CVE-2022-29531 | Med | 0.35 | 5.4 | 0.01 | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name. | ||
| CVE-2022-29530 | Med | 0.35 | 5.4 | 0.01 | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters. | ||
| CVE-2022-29529 | Med | 0.35 | 5.4 | 0.01 | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field. | ||
| CVE-2021-37743 | Med | 0.35 | 5.4 | 0.01 | Jul 30, 2021 | app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format. | ||
| CVE-2021-37742 | Med | 0.35 | 5.4 | 0.01 | Jul 30, 2021 | app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships. | ||
| CVE-2021-37534 | Med | 0.35 | 5.4 | 0.01 | Jul 26, 2021 | app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster. | ||
| CVE-2019-19379 | Med | 0.35 | 5.3 | 0.01 | Nov 28, 2019 | In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data. | ||
| CVE-2019-16202 | Med | 0.35 | 6.5 | 0.01 | Sep 10, 2019 | MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP… |
- risk 0.37cvss 6.8epss 0.00
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without first rotating the session…
- risk 0.36cvss 5.5epss 0.00
In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.
- risk 0.36cvss 5.5epss 0.00
In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.
- risk 0.35cvss —epss —
When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report…
- risk 0.35cvss 6.5epss 0.00
Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive fields such as: * type…
- risk 0.35cvss 6.5epss 0.00
Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring template-management operations. The upload…
- risk 0.35cvss 6.5epss 0.00
A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed semantic validation when the…
- risk 0.35cvss 6.5epss 0.00
A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to missing parentheses in the delete condition, the expression was evaluated as ($validationError === null && POST) || DELETE,…
- risk 0.35cvss 6.5epss 0.00
A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the record. Because the underlying framework treats a supplied primary key as an…
- risk 0.35cvss 5.4epss 0.00
In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.
- risk 0.35cvss 5.4epss 0.01
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
- risk 0.35cvss 5.4epss 0.01
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.
- risk 0.35cvss 5.4epss 0.01
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.
- risk 0.35cvss 5.4epss 0.01
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
- risk 0.35cvss 5.3epss 0.01
In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.
- risk 0.35cvss 6.5epss 0.01
MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP…
Page 7 of 11