VYPR

Misp

by Misp

Source repositories

CVEs (217)

  • CVE-2022-27244MedMar 18, 2022
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered in MISP before 2.4.156. A malicious site administrator could store an XSS payload in the custom auth name. This would be executed each time the administrator modifies a user.

  • CVE-2026-86440MedSep 7, 2026
    risk 0.28cvss 5.4epss 0.00

    Affected versions of MISP insufficiently validate URLs used by dashboard widgets, particularly the Button widget. The widget's URL is stored configuration controlled by a user. The previous renderer considered a URL safe if it appeared relative or if its parsed hostname…

  • CVE-2026-85230MedSep 3, 2026
    risk 0.28cvss 5.4epss 0.00

    A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were not validated when the configuration was saved. As a result, an authenticated user able to…

  • CVE-2026-44381MedMay 13, 2026
    risk 0.28cvss 5.3epss 0.01

    MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow attribute listing endpoints. The affected code accepted order or sort values…

  • CVE-2026-8080MedMay 7, 2026
    risk 0.28cvss 5.4epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue affects MISP before 2.5.37. A stored cross-site scripting vulnerability exists in the template element attribute handling…

  • CVE-2024-57969MedFeb 14, 2025
    risk 0.28cvss 4.3epss 0.00

    app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.

  • CVE-2022-42724MedOct 10, 2022
    risk 0.28cvss 4.3epss 0.00

    app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).

  • CVE-2020-15412MedJun 30, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.

  • CVE-2026-95805MedSep 22, 2026
    risk 0.27cvss —epss —

    A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a trailing asterisk) instead of the correct 'theming_enabled'. In the MISP ACL system, the array…

  • CVE-2026-95698MedSep 22, 2026
    risk 0.27cvss —epss —

    The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organization identifier with a fixed image directory and a file extension, then calls file_exists() on the resulting path. The organization name field is…

  • CVE-2026-95697MedSep 22, 2026
    risk 0.27cvss —epss —

    MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata fields without verifying that the invoking user holds sufficient privileges. A user with a…

  • CVE-2026-95693MedSep 22, 2026
    risk 0.27cvss —epss —

    In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP upload via is_uploaded_file(). An…

  • CVE-2026-95685MedSep 22, 2026
    risk 0.27cvss —epss —

    MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of suggestion content within an event report, was incorrectly mapped to the wildcard permission ('*') in the ACLComponent, making it accessible…

  • CVE-2026-95683MedSep 22, 2026
    risk 0.27cvss —epss —

    In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrichment logic fetched the report using only the event ID as the lookup condition, without applying the report's own distribution/ACL constraints. Because MISP…

  • CVE-2026-95674MedSep 22, 2026
    risk 0.27cvss —epss —

    In MISP, the queryEnrichment method in EventsController.php accepted a module name parameter and iterated over the list of enabled modules to find a match. If the specified module was not present in the enabled modules list, the code silently continued processing using default…

  • CVE-2026-95671MedSep 22, 2026
    risk 0.27cvss —epss —

    In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and element capture only when the HTTP request method was POST. However, the underlying CRUDComponent::add() method persists data on both POST and PUT requests. As a result,…

  • CVE-2026-91859MedSep 15, 2026
    risk 0.27cvss —epss 0.00

    Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time. As a result, __accessMonitor() calls…

  • CVE-2026-91857MedSep 15, 2026
    risk 0.27cvss —epss 0.00

    Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are:  - EventReportsController::purgeUnusedPictures()  - NoticelistsController::enableNoticelist() …

  • CVE-2026-91851MedSep 15, 2026
    risk 0.27cvss —epss 0.00

    Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when either:  - its restrict_to_permission_flag matched one of the current user’s permission…

  • CVE-2026-54398MedJun 12, 2026
    risk 0.27cvss —epss 0.00

    An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing group that the user was not authorized to use or view. When editing objects,…