VYPR

Vendor CVEs

Misp

All CVEs

242 total · sorted by risk
  • CVE-2020-13153MedMay 18, 2020
    risk 0.40cvss 6.1epss 0.01

    app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.

  • CVE-2020-10247MedMar 9, 2020
    risk 0.40cvss 6.1epss 0.01

    MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp.

  • CVE-2020-10246MedMar 9, 2020
    risk 0.40cvss 6.1epss 0.01

    MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.

  • CVE-2019-14286MedJul 27, 2019
    risk 0.40cvss 6.1epss 0.01

    In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user toggles the event graph view. A malicious MISP event must be crafted in order to trigger the vulnerability.

  • CVE-2019-11814MedMay 8, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in titles, as demonstrated by a screenshot.

  • CVE-2019-11813MedMay 8, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS via link type attributes with javascript:// links.

  • CVE-2019-11812MedMay 8, 2019
    risk 0.40cvss 6.1epss 0.01

    A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion interface, and can be triggered by clicking on the link.

  • CVE-2019-10254MedMar 28, 2019
    risk 0.40cvss 6.1epss 0.01

    In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability.

  • CVE-2018-11562MedMay 30, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter.

  • CVE-2017-15216MedOct 10, 2017
    risk 0.40cvss 6.1epss 0.01

    MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.

  • CVE-2017-13671MedAug 24, 2017
    risk 0.40cvss 6.1epss 0.01

    app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.

  • CVE-2017-7215MedMar 21, 2017
    risk 0.40cvss 6.1epss 0.02

    Cross site scripting in some view elements in the index filter tool in app/webroot/js/misp2.4.68.js and the organisation landing page in app/View/Organisations/ajax/landingpage.ctp of MISP before 2.4.69 allows remote attackers to inject arbitrary web script or HTML.

  • CVE-2026-94404HigSep 21, 2026
    risk 0.39cvss —epss —

    MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protection against forged requests. Because…

  • CVE-2026-91846HigSep 15, 2026
    risk 0.39cvss —epss 0.00

    Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselves only store UUIDs, while the collection…

  • CVE-2026-91825HigSep 15, 2026
    risk 0.39cvss —epss 0.00

    Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distribution = 4. If the attacker instead omitted…

  • CVE-2026-88915HigSep 10, 2026
    risk 0.39cvss —epss 0.00

    Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed that value into event creation without…

  • CVE-2026-86283HigSep 6, 2026
    risk 0.39cvss —epss 0.00

    MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs…

  • CVE-2026-54359HigJun 12, 2026
    risk 0.39cvss —epss 0.00

    MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests such as POST, PUT, or AJAX requests are not restricted based on the browser-provided Sec-Fetch-Site…

  • CVE-2026-95754MedSep 22, 2026
    risk 0.38cvss —epss —

    In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The query selected only User.password, User.totp, and…

  • CVE-2026-95679MedSep 22, 2026
    risk 0.38cvss —epss —

    MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build() library contains a logic error in its readFile guard condition (readFile && http || https), where PHP operator precedence causes the https branch to bypass…

  • CVE-2026-95667MedSep 22, 2026
    risk 0.38cvss —epss —

    The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_install.log and a named pipe (FIFO) at /var/log/misp_install.log.pipe to capture all installer output. The log captures highly sensitive data including the…

  • CVE-2026-95658MedSep 22, 2026
    risk 0.38cvss —epss —

    MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation for that action. Because…

  • CVE-2026-94379MedSep 21, 2026
    risk 0.38cvss —epss —

    The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PUT) before enforcing bruteforce protection,…

  • CVE-2026-92003MedSep 15, 2026
    risk 0.38cvss —epss 0.00

    Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model:  - API requests with no authentication key;  - requests supplying an API key with an…

  • CVE-2026-91819MedSep 15, 2026
    risk 0.38cvss —epss 0.00

    Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For override values outside the…

  • CVE-2026-77710MedAug 21, 2026
    risk 0.38cvss —epss 0.00

    A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the…

  • CVE-2026-72759MedAug 10, 2026
    risk 0.38cvss —epss 0.00

    In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization check. When a history record references a deleted conversion, the associated conversion lookup returns None. The previous logic only denied access when the…

  • CVE-2026-53693MedJun 10, 2026
    risk 0.38cvss —epss 0.00

    A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, collection names, entity identifiers, cluster names, and tag metadata directly into HTML, HTML attributes, inline JavaScript event…

  • CVE-2020-8891MedFeb 12, 2020
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.

  • CVE-2020-8890MedFeb 12, 2020
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests.

  • CVE-2026-85238MedSep 3, 2026
    risk 0.37cvss 6.8epss 0.00

    MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without first rotating the session…

  • CVE-2024-58129MedMar 28, 2025
    risk 0.36cvss 5.5epss 0.00

    In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.

  • CVE-2024-58128MedMar 28, 2025
    risk 0.36cvss 5.5epss 0.00

    In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.

  • CVE-2021-27904MedMar 2, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.

  • CVE-2026-94393MedSep 21, 2026
    risk 0.35cvss —epss —

    When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on one event could potentially move a report…

  • CVE-2026-86408MedSep 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKeysController::view(). The vulnerable handler queried CryptographicKey directly using the supplied key ID and selected sensitive fields such as: * type…

  • CVE-2026-86347MedSep 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring template-management operations. The upload…

  • CVE-2026-85239MedSep 3, 2026
    risk 0.35cvss 6.5epss 0.00

    A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed semantic validation when the…

  • CVE-2026-10860MedJun 4, 2026
    risk 0.35cvss 6.5epss 0.00

    A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to missing parentheses in the delete condition, the expression was evaluated as ($validationError === null && POST) || DELETE,…

  • CVE-2026-9136MedMay 20, 2026
    risk 0.35cvss 6.5epss 0.00

    A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the record. Because the underlying framework treats a supplied primary key as an…

  • CVE-2025-67906MedDec 15, 2025
    risk 0.35cvss 5.4epss 0.00

    In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

  • CVE-2023-37307MedJun 30, 2023
    risk 0.35cvss 5.4epss 0.01

    In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.

  • CVE-2022-29531MedApr 20, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.

  • CVE-2022-29530MedApr 20, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.

  • CVE-2022-29529MedApr 20, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.

  • CVE-2021-37743MedJul 30, 2021
    risk 0.35cvss 5.4epss 0.01

    app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.

  • CVE-2021-37742MedJul 30, 2021
    risk 0.35cvss 5.4epss 0.01

    app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.

  • CVE-2021-37534MedJul 26, 2021
    risk 0.35cvss 5.4epss 0.01

    app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.

  • CVE-2019-19379MedNov 28, 2019
    risk 0.35cvss 5.3epss 0.01

    In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.

  • CVE-2019-16202MedSep 10, 2019
    risk 0.35cvss 6.5epss 0.01

    MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP…