VYPR

Vendor CVEs

Misp

All CVEs

242 total · sorted by risk
  • CVE-2026-54361HigJun 12, 2026
    risk 0.50cvss —epss 0.00

    MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Several controller actions accepted user-supplied fields that should have remained server-controlled, including record identifiers…

  • CVE-2026-94383HigSep 21, 2026
    risk 0.49cvss —epss —

    The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path components and a check for empty or dot values. A site administrator could specify a…

  • CVE-2026-85546HigSep 4, 2026
    risk 0.49cvss —epss 0.00

    MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, where the HTTP method validation intended to restrict these…

  • CVE-2023-37306HigJun 30, 2023
    risk 0.49cvss 7.5epss 0.01

    MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

  • CVE-2022-29534HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.

  • CVE-2021-31780HigApr 23, 2021
    risk 0.49cvss 7.5epss 0.01

    In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is…

  • CVE-2020-28043HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.01

    MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.

  • CVE-2020-25766HigSep 18, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.

  • CVE-2020-14969HigJun 22, 2020
    risk 0.49cvss 7.5epss 0.01

    app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.

  • CVE-2020-8893HigFeb 12, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp.

  • CVE-2026-93296HigSep 17, 2026
    risk 0.48cvss —epss 0.00

    MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card and the server/feed preview card constructed donut chart legend labels by directly concatenating object name or category keys into an innerHTML string…

  • CVE-2026-90895HigSep 14, 2026
    risk 0.48cvss —epss 0.00

    Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web application in multiple security-sensitive…

  • CVE-2026-54360HigJun 12, 2026
    risk 0.48cvss —epss 0.00

    A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the controller did not remove a user-supplied id field before saving the submitted data. In CakePHP, supplying a primary key in the save data can cause a…

  • CVE-2026-94401HigSep 21, 2026
    risk 0.47cvss —epss —

    MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was actually XML. Because of this, a user with…

  • CVE-2026-94374HigSep 21, 2026
    risk 0.47cvss —epss —

    MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves each one. Unlike the adjacent attribute…

  • CVE-2026-85538HigSep 4, 2026
    risk 0.47cvss —epss 0.00

    An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions. The affected attribute deletion paths relied on organization membership checks performed by…

  • CVE-2024-58130HigMar 28, 2025
    risk 0.47cvss 7.2epss 0.00

    In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.

  • CVE-2019-12868HigJun 18, 2019
    risk 0.47cvss 7.2epss 0.06

    app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.

  • CVE-2018-6926HigFeb 12, 2018
    risk 0.47cvss 7.2epss 0.01

    In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The…

  • CVE-2026-85237HigSep 3, 2026
    risk 0.46cvss 8.1epss 0.00

    A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating submitted OTP values. An attacker…

  • CVE-2026-10863HigJun 4, 2026
    risk 0.46cvss 8.1epss 0.00

    A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user to override the server-defined ordering of over-correlating values. Depending…

  • CVE-2026-95806HigSep 22, 2026
    risk 0.43cvss —epss —

    MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point.  The phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences:    - any filesystem operation on a…

  • CVE-2019-12794MedJun 11, 2019
    risk 0.43cvss 6.6epss 0.01

    An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability to reset passwords for all of their organization's users). This, however, could be abused in a situation where the host…

  • CVE-2026-86452HigSep 7, 2026
    risk 0.42cvss 7.5epss 0.00

    Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a…

  • CVE-2026-85533HigSep 4, 2026
    risk 0.42cvss —epss 0.00

    An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing Group. In several attribute and Galaxy Cluster creation and editing workflows, validation of the submitted…

  • CVE-2026-54358HigJun 12, 2026
    risk 0.42cvss —epss 0.00

    An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization through the administrative email functionality. The affected code restricted organization administrators to users within…

  • CVE-2026-9137HigMay 20, 2026
    risk 0.42cvss 7.5epss 0.00

    The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and…

  • CVE-2024-45509MedSep 1, 2024
    risk 0.42cvss 6.5epss 0.00

    In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

  • CVE-2020-8894MedFeb 12, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsController.php and app/Model/Thread.php.

  • CVE-2026-56447HigJun 22, 2026
    risk 0.40cvss 7.2epss 0.01

    MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled configuration file could use rdkafka…

  • CVE-2026-56446HigJun 22, 2026
    risk 0.40cvss 7.2epss 0.01

    MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated attacker with site administrator privileges could direct log output to a PHP…

  • CVE-2026-44380HigMay 13, 2026
    risk 0.40cvss 7.2epss 0.00

    MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys belonging to site…

  • CVE-2023-49926MedDec 3, 2023
    risk 0.40cvss 6.1epss 0.00

    app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.

  • CVE-2023-41098MedAug 23, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit.

  • CVE-2023-40224MedAug 10, 2023
    risk 0.40cvss 6.1epss 0.00

    MISP 2.4.174 allows XSS in app/View/Events/index.ctp.

  • CVE-2023-28884MedMar 27, 2023
    risk 0.40cvss 6.1epss 0.00

    In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.

  • CVE-2023-28607MedMar 18, 2023
    risk 0.40cvss 6.1epss 0.00

    js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.

  • CVE-2023-28606MedMar 18, 2023
    risk 0.40cvss 6.1epss 0.00

    js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.

  • CVE-2023-24070MedJan 23, 2023
    risk 0.40cvss 6.1epss 0.00

    app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.

  • CVE-2023-24027MedJan 20, 2023
    risk 0.40cvss 6.1epss 0.00

    In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.

  • CVE-2022-47928MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.00

    In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.

  • CVE-2022-29533MedApr 20, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page."

  • CVE-2022-27246MedMar 18, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default.

  • CVE-2021-36212MedJul 7, 2021
    risk 0.40cvss 6.1epss 0.01

    app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.

  • CVE-2020-24085MedJan 26, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious JavaScript code.

  • CVE-2021-3184MedJan 19, 2021
    risk 0.40cvss 6.1epss 0.01

    MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.

  • CVE-2021-25325MedJan 19, 2021
    risk 0.40cvss 6.1epss 0.01

    MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.

  • CVE-2021-25324MedJan 19, 2021
    risk 0.40cvss 6.1epss 0.01

    MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.

  • CVE-2020-29572MedDec 6, 2020
    risk 0.40cvss 6.1epss 0.01

    app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.

  • CVE-2020-28947MedNov 19, 2020
    risk 0.40cvss 6.1epss 0.01

    In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.

Page 2 of 5