Vendor CVEs
Misp
All CVEs
242 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-54361 | Hig | 0.50 | — | 0.00 | Jun 12, 2026 | MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Several controller actions accepted user-supplied fields that should have remained server-controlled, including record identifiers… | ||
| CVE-2026-94383 | Hig | 0.49 | — | — | Sep 21, 2026 | The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path components and a check for empty or dot values. A site administrator could specify a… | ||
| CVE-2026-85546 | Hig | 0.49 | — | 0.00 | Sep 4, 2026 | MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, where the HTTP method validation intended to restrict these… | ||
| CVE-2023-37306 | Hig | 0.49 | 7.5 | 0.01 | Jun 30, 2023 | MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages. | ||
| CVE-2022-29534 | Hig | 0.49 | 7.5 | 0.02 | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header. | ||
| CVE-2021-31780 | Hig | 0.49 | 7.5 | 0.01 | Apr 23, 2021 | In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is… | ||
| CVE-2020-28043 | Hig | 0.49 | 7.5 | 0.01 | Nov 2, 2020 | MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL. | ||
| CVE-2020-25766 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2020 | An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page. | ||
| CVE-2020-14969 | Hig | 0.49 | 7.5 | 0.01 | Jun 22, 2020 | app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute. | ||
| CVE-2020-8893 | Hig | 0.49 | 7.5 | 0.02 | Feb 12, 2020 | An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp. | ||
| CVE-2026-93296 | Hig | 0.48 | — | 0.00 | Sep 17, 2026 | MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card and the server/feed preview card constructed donut chart legend labels by directly concatenating object name or category keys into an innerHTML string… | ||
| CVE-2026-90895 | Hig | 0.48 | — | 0.00 | Sep 14, 2026 | Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web application in multiple security-sensitive… | ||
| CVE-2026-54360 | Hig | 0.48 | — | 0.00 | Jun 12, 2026 | A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a user-supplied id field before saving the submitted data. In CakePHP, supplying a primary key in the save data can cause a… | ||
| CVE-2026-94401 | Hig | 0.47 | — | — | Sep 21, 2026 | MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was actually XML. Because of this, a user with… | ||
| CVE-2026-94374 | Hig | 0.47 | — | — | Sep 21, 2026 | MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves each one. Unlike the adjacent attribute… | ||
| CVE-2026-85538 | Hig | 0.47 | — | 0.00 | Sep 4, 2026 | An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions. The affected attribute deletion paths relied on organization membership checks performed by… | ||
| CVE-2024-58130 | Hig | 0.47 | 7.2 | 0.00 | Mar 28, 2025 | In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses. | ||
| CVE-2019-12868 | Hig | 0.47 | 7.2 | 0.06 | Jun 18, 2019 | app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization. | ||
| CVE-2018-6926 | Hig | 0.47 | 7.2 | 0.01 | Feb 12, 2018 | In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The… | ||
| CVE-2026-85237 | Hig | 0.46 | 8.1 | 0.00 | Sep 3, 2026 | A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating submitted OTP values. An attacker… | ||
| CVE-2026-10863 | Hig | 0.46 | 8.1 | 0.00 | Jun 4, 2026 | A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user to override the server-defined ordering of over-correlating values. Depending… | ||
| CVE-2026-95806 | Hig | 0.43 | — | — | Sep 22, 2026 | MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences: - any filesystem operation on a… | ||
| CVE-2019-12794 | Med | 0.43 | 6.6 | 0.01 | Jun 11, 2019 | An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability to reset passwords for all of their organization's users). This, however, could be abused in a situation where the host… | ||
| CVE-2026-86452 | Hig | 0.42 | 7.5 | 0.00 | Sep 7, 2026 | Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a… | ||
| CVE-2026-85533 | Hig | 0.42 | — | 0.00 | Sep 4, 2026 | An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing Group. In several attribute and Galaxy Cluster creation and editing workflows, validation of the submitted… | ||
| CVE-2026-54358 | Hig | 0.42 | — | 0.00 | Jun 12, 2026 | An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization through the administrative email functionality. The affected code restricted organization administrators to users within… | ||
| CVE-2026-9137 | Hig | 0.42 | 7.5 | 0.00 | May 20, 2026 | The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and… | ||
| CVE-2024-45509 | Med | 0.42 | 6.5 | 0.00 | Sep 1, 2024 | In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin. | ||
| CVE-2020-8894 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2020 | An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsController.php and app/Model/Thread.php. | ||
| CVE-2026-56447 | Hig | 0.40 | 7.2 | 0.01 | Jun 22, 2026 | MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled configuration file could use rdkafka… | ||
| CVE-2026-56446 | Hig | 0.40 | 7.2 | 0.01 | Jun 22, 2026 | MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated attacker with site administrator privileges could direct log output to a PHP… | ||
| CVE-2026-44380 | Hig | 0.40 | 7.2 | 0.00 | May 13, 2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys belonging to site… | ||
| CVE-2023-49926 | Med | 0.40 | 6.1 | 0.00 | Dec 3, 2023 | app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget. | ||
| CVE-2023-41098 | Med | 0.40 | 6.1 | 0.00 | Aug 23, 2023 | An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit. | ||
| CVE-2023-40224 | Med | 0.40 | 6.1 | 0.00 | Aug 10, 2023 | MISP 2.4.174 allows XSS in app/View/Events/index.ctp. | ||
| CVE-2023-28884 | Med | 0.40 | 6.1 | 0.00 | Mar 27, 2023 | In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index. | ||
| CVE-2023-28607 | Med | 0.40 | 6.1 | 0.00 | Mar 18, 2023 | js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip. | ||
| CVE-2023-28606 | Med | 0.40 | 6.1 | 0.00 | Mar 18, 2023 | js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips. | ||
| CVE-2023-24070 | Med | 0.40 | 6.1 | 0.00 | Jan 23, 2023 | app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field. | ||
| CVE-2023-24027 | Med | 0.40 | 6.1 | 0.00 | Jan 20, 2023 | In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name. | ||
| CVE-2022-47928 | Med | 0.40 | 6.1 | 0.00 | Dec 22, 2022 | In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp. | ||
| CVE-2022-29533 | Med | 0.40 | 6.1 | 0.01 | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page." | ||
| CVE-2022-27246 | Med | 0.40 | 6.1 | 0.01 | Mar 18, 2022 | An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default. | ||
| CVE-2021-36212 | Med | 0.40 | 6.1 | 0.01 | Jul 7, 2021 | app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view. | ||
| CVE-2020-24085 | Med | 0.40 | 6.1 | 0.01 | Jan 26, 2021 | A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious JavaScript code. | ||
| CVE-2021-3184 | Med | 0.40 | 6.1 | 0.01 | Jan 19, 2021 | MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button. | ||
| CVE-2021-25325 | Med | 0.40 | 6.1 | 0.01 | Jan 19, 2021 | MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs. | ||
| CVE-2021-25324 | Med | 0.40 | 6.1 | 0.01 | Jan 19, 2021 | MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp. | ||
| CVE-2020-29572 | Med | 0.40 | 6.1 | 0.01 | Dec 6, 2020 | app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field. | ||
| CVE-2020-28947 | Med | 0.40 | 6.1 | 0.01 | Nov 19, 2020 | In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled. |
- risk 0.50cvss —epss 0.00
MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Several controller actions accepted user-supplied fields that should have remained server-controlled, including record identifiers…
- risk 0.49cvss —epss —
The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path components and a check for empty or dot values. A site administrator could specify a…
- risk 0.49cvss —epss 0.00
MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, where the HTTP method validation intended to restrict these…
- risk 0.49cvss 7.5epss 0.01
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.
- risk 0.49cvss 7.5epss 0.01
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is…
- risk 0.49cvss 7.5epss 0.01
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.
- risk 0.49cvss 7.5epss 0.01
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp.
- risk 0.48cvss —epss 0.00
MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card and the server/feed preview card constructed donut chart legend labels by directly concatenating object name or category keys into an innerHTML string…
- risk 0.48cvss —epss 0.00
Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web application in multiple security-sensitive…
- risk 0.48cvss —epss 0.00
A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a user-supplied id field before saving the submitted data. In CakePHP, supplying a primary key in the save data can cause a…
- risk 0.47cvss —epss —
MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was actually XML. Because of this, a user with…
- risk 0.47cvss —epss —
MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves each one. Unlike the adjacent attribute…
- risk 0.47cvss —epss 0.00
An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions. The affected attribute deletion paths relied on organization membership checks performed by…
- risk 0.47cvss 7.2epss 0.00
In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.
- risk 0.47cvss 7.2epss 0.06
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.
- risk 0.47cvss 7.2epss 0.01
In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The…
- risk 0.46cvss 8.1epss 0.00
A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating submitted OTP values. An attacker…
- risk 0.46cvss 8.1epss 0.00
A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user to override the server-defined ordering of over-correlating values. Depending…
- risk 0.43cvss —epss —
MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences: - any filesystem operation on a…
- risk 0.43cvss 6.6epss 0.01
An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability to reset passwords for all of their organization's users). This, however, could be abused in a situation where the host…
- risk 0.42cvss 7.5epss 0.00
Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a…
- risk 0.42cvss —epss 0.00
An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing Group. In several attribute and Galaxy Cluster creation and editing workflows, validation of the submitted…
- risk 0.42cvss —epss 0.00
An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization through the administrative email functionality. The affected code restricted organization administrators to users within…
- risk 0.42cvss 7.5epss 0.00
The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and…
- risk 0.42cvss 6.5epss 0.00
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsController.php and app/Model/Thread.php.
- risk 0.40cvss 7.2epss 0.01
MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled configuration file could use rdkafka…
- risk 0.40cvss 7.2epss 0.01
MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated attacker with site administrator privileges could direct log output to a PHP…
- risk 0.40cvss 7.2epss 0.00
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys belonging to site…
- risk 0.40cvss 6.1epss 0.00
app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.
- risk 0.40cvss 6.1epss 0.00
An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit.
- risk 0.40cvss 6.1epss 0.00
MISP 2.4.174 allows XSS in app/View/Events/index.ctp.
- risk 0.40cvss 6.1epss 0.00
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
- risk 0.40cvss 6.1epss 0.00
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
- risk 0.40cvss 6.1epss 0.00
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
- risk 0.40cvss 6.1epss 0.00
app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
- risk 0.40cvss 6.1epss 0.00
In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
- risk 0.40cvss 6.1epss 0.00
In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page."
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default.
- risk 0.40cvss 6.1epss 0.01
app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious JavaScript code.
- risk 0.40cvss 6.1epss 0.01
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
- risk 0.40cvss 6.1epss 0.01
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.
- risk 0.40cvss 6.1epss 0.01
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
- risk 0.40cvss 6.1epss 0.01
app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.
- risk 0.40cvss 6.1epss 0.01
In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.
Page 2 of 5