VYPR

Vendor CVEs

Misp

All CVEs

165 total · sorted by risk
  • CVE-2024-29859CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.

  • CVE-2024-29858CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.00

    In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.

  • CVE-2024-25675CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.

  • CVE-2024-25674CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.

  • CVE-2023-50918CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.

  • CVE-2023-48659CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.

  • CVE-2023-48658CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.

  • CVE-2023-48657CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.

  • CVE-2023-48656CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.

  • CVE-2023-48655CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.

  • CVE-2022-48329CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.

  • CVE-2022-48328CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

  • CVE-2022-29528CriApr 20, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.

  • CVE-2021-41326CriSep 17, 2021
    risk 0.64cvss 9.8epss 0.02

    In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.

  • CVE-2021-39302CriAug 19, 2021
    risk 0.64cvss 9.8epss 0.01

    MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.

  • CVE-2021-35502CriJun 25, 2021
    risk 0.64cvss 9.8epss 0.01

    app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index.

  • CVE-2020-29006CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.01

    MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.

  • CVE-2020-15411CriJun 30, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader.

  • CVE-2018-12649CriJun 22, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP method instead of a POST HTTP method in the login part, because this protection was only covering POST requests.

  • CVE-2018-19908HigDec 6, 2018
    risk 0.62cvss 8.8epss 0.17

    An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious authenticated user to execute arbitrary commands by tweaking…

  • CVE-2021-25323CriJan 19, 2021
    risk 0.59cvss 9.1epss 0.01

    The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.

  • CVE-2026-10611CriJun 2, 2026
    risk 0.58cvss 10.0epss 0.00

    An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users authenticated through an authentication plugin, such as LDAP, may…

  • CVE-2022-27245HigMar 18, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.

  • CVE-2020-15711HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.00

    In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.

  • CVE-2020-12889CriMay 15, 2020
    risk 0.57cvss 9.8epss 0.01

    MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case.

  • CVE-2015-5721CriSep 3, 2016
    risk 0.57cvss 9.8epss 0.03

    Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.

  • CVE-2015-5719CriSep 3, 2016
    risk 0.57cvss 9.8epss 0.02

    app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.

  • CVE-2026-39962CriApr 9, 2026
    risk 0.55cvss 9.6epss 0.00

    MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheAuthenticate.apacheEnv is configured to use…

  • CVE-2026-56422CriJun 22, 2026
    risk 0.54cvss epss 0.01

    Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uuid, and related nested object…

  • CVE-2025-66384HigNov 28, 2025
    risk 0.53cvss 8.2epss 0.00

    app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.

  • CVE-2020-8892HigFeb 12, 2020
    risk 0.53cvss 8.1epss 0.02

    An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-force series of invalid requests.

  • CVE-2017-14337HigSep 12, 2017
    risk 0.53cvss 8.1epss 0.01

    When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST API, if an external user provides X.509 certificate authentication and this API returns an empty value, the unauthenticated user…

  • CVE-2026-10868CriJun 4, 2026
    risk 0.52cvss epss 0.00

    A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the application accepted a user-controlled User.id value from request data. An…

  • CVE-2022-27243HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom terms file setting.

  • CVE-2026-73160HigAug 11, 2026
    risk 0.50cvss epss 0.00

    Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplied hostname was itself an IP literal and rejected private, loopback, link-local, or reserved IPs.…

  • CVE-2026-69082HigAug 3, 2026
    risk 0.50cvss epss 0.00

    CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/ endpoint accepted HTTP GET requests for an operation that modified application state. An unauthenticated remote attacker could…

  • CVE-2026-69079HigAug 3, 2026
    risk 0.50cvss epss 0.00

    CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a reasonable range. A remote, unauthenticated attacker could…

  • CVE-2026-69078HigAug 3, 2026
    risk 0.50cvss epss 0.00

    CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI content, including conversion names, descriptions, and comments, is converted from Markdown to HTML and rendered as a PDF using…

  • CVE-2026-56425HigJun 22, 2026
    risk 0.50cvss 8.8epss 0.00

    The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. The application used the PHP session identifier…

  • CVE-2026-56424HigJun 22, 2026
    risk 0.50cvss 8.8epss 0.00

    MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged authenticated user with the relevant feature…

  • CVE-2026-56423HigJun 22, 2026
    risk 0.50cvss 8.8epss 0.00

    MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level permissions instead of validating authorization for each selected object. For…

  • CVE-2026-54361HigJun 12, 2026
    risk 0.50cvss epss 0.00

    MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Several controller actions accepted user-supplied fields that should have remained server-controlled, including record identifiers…

  • CVE-2023-37306HigJun 30, 2023
    risk 0.49cvss 7.5epss 0.01

    MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

  • CVE-2022-29534HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.

  • CVE-2021-31780HigApr 23, 2021
    risk 0.49cvss 7.5epss 0.01

    In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is…

  • CVE-2020-28043HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.01

    MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.

  • CVE-2020-25766HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.

  • CVE-2020-14969HigJun 22, 2020
    risk 0.49cvss 7.5epss 0.01

    app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.

  • CVE-2020-8893HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp.

  • CVE-2026-54360HigJun 12, 2026
    risk 0.48cvss epss 0.00

    A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a user-supplied id field before saving the submitted data. In CakePHP, supplying a primary key in the save data can cause a…

Page 1 of 4