VYPR

Misp

by Misp

Source repositories

CVEs (217)

  • CVE-2019-9482MedMar 1, 2019
    risk 0.35cvss 5.3epss 0.01

    In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only).

  • CVE-2017-16802MedNov 13, 2017
    risk 0.35cvss 5.4epss 0.01

    In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.

  • CVE-2026-94394MedSep 21, 2026
    risk 0.34cvss —epss —

    When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user. Because of this, someone who can view an event could…

  • CVE-2026-94373MedSep 21, 2026
    risk 0.34cvss —epss —

    MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML elements by assigning user-controllable values to the innerHTML property. Because innerHTML parses and renders HTML…

  • CVE-2026-94372MedSep 21, 2026
    risk 0.34cvss —epss —

    MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP instance detects unknown custom or default galaxy clusters during synchronization, it renders sample tag names in an informational notice directed at site…

  • CVE-2026-94277MedSep 21, 2026
    risk 0.34cvss —epss —

    MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding. An authenticated user holding the perm_galaxy_editor permission can create or modify a galaxy whose name…

  • CVE-2026-86351MedSep 7, 2026
    risk 0.33cvss 6.1epss 0.00

    Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs such as //attacker.example also begin with / but resolve to an external origin in browsers. The…

  • CVE-2026-85547MedSep 4, 2026
    risk 0.33cvss —epss 0.00

    A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identified as a REST request. MISP's REST detection can be influenced by request properties such as the URL suffix…

  • CVE-2026-85227MedSep 3, 2026
    risk 0.33cvss 6.1epss 0.00

    MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL parameters were inserted into the query-builder rules without HTML escaping before being serialized as JSON…

  • CVE-2026-54397MedJun 12, 2026
    risk 0.33cvss —epss 0.00

    A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manipulate the submitted form data and set an event’s sharing_group_id to a sharing group they were not authorized to use. When distribution was set to sharing…

  • CVE-2026-10861MedJun 4, 2026
    risk 0.33cvss 6.1epss 0.00

    An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key was used as the post-login redirect destination without sufficiently enforcing that it was a local application path. An…

  • CVE-2026-10856MedJun 4, 2026
    risk 0.33cvss 6.1epss 0.00

    A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpreted by browsers as an external URL. The validation rejected URLs containing an explicit scheme, host, or user component, but did…

  • CVE-2024-54675MedDec 4, 2024
    risk 0.33cvss 6.1epss 0.00

    app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ad-hoc workflow.

  • CVE-2024-54674MedDec 4, 2024
    risk 0.33cvss 6.1epss 0.00

    app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom clusters into the misp-galaxy format.

  • CVE-2015-5720MedSep 3, 2016
    risk 0.33cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edit.ctp, and (3)…

  • CVE-2026-9084MedMay 20, 2026
    risk 0.32cvss —epss 0.00

    MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecure or untrusted IdP configurations where email ownership is not enforced, an…

  • CVE-2024-46918MedSep 15, 2024
    risk 0.32cvss 4.9epss 0.00

    app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.

  • CVE-2020-11458MedApr 2, 2020
    risk 0.32cvss 4.9epss 0.01

    app/Model/feed.php in MISP before 2.4.124 allows administrators to choose arbitrary files that should be ingested by MISP. This does not cause a leak of the full contents of a file, but does cause a leaks of strings that match certain patterns. Among the data that can leak are…

  • CVE-2017-16946MedNov 25, 2017
    risk 0.32cvss 4.9epss 0.01

    The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.

  • CVE-2022-29532MedApr 20, 2022
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.

Page 8 of 11