VendorsMISP-Projectmispall versions
Vulnerabilities

MISP-Project MISP Project MISP (Malware Information Sharing Platform)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

141CVEs
CVE-2015-5719
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.
Published 2016-09-03 · Modified
10.0EPSS 0.023
CVE-2026-10611
OTP bypass via plugin-based LDAP authentication in MISP when LDAP mixed authentication is enabled
Published 2026-06-02 · Analyzed
10.0EPSS 0.004
CVE-2015-5721
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.
Published 2016-09-03 · Modified
9.8EPSS 0.026
CVE-2022-29528
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
Published 2022-04-20 · Modified
9.8EPSS 0.022
CVE-2021-41326
In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.
Published 2021-09-17 · Modified
9.8EPSS 0.018
CVE-2018-12649
An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP method instead of a POST HTTP method in the login part, because this protection was only covering POST requests.
Published 2018-06-22 · Modified
9.8EPSS 0.015
CVE-2020-15411
An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader.
Published 2020-06-30 · Modified
9.8EPSS 0.015
CVE-2022-48328
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
Published 2023-02-20 · Modified
9.8EPSS 0.013
CVE-2020-29006
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
Published 2020-11-24 · Modified
9.8EPSS 0.013
CVE-2021-35502
app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-template:index.
Published 2021-06-25 · Modified
9.8EPSS 0.011
CVE-2021-39302
MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.
Published 2021-08-19 · Modified
9.8EPSS 0.009
CVE-2022-48329
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
Published 2023-02-20 · Modified
9.8EPSS 0.009
CVE-2023-48659
An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
Published 2023-11-17 · Modified
9.8EPSS 0.009
CVE-2023-48657
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
Published 2023-11-17 · Modified
9.8EPSS 0.009
CVE-2023-48655
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
Published 2023-11-17 · Modified
9.8EPSS 0.009
CVE-2023-48658
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.
Published 2023-11-17 · Modified
9.8EPSS 0.009
CVE-2023-48656
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
Published 2023-11-17 · Modified
9.8EPSS 0.009
CVE-2026-85216
MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials
Published 2026-09-03 · Analyzed
9.8EPSS 0.009
CVE-2024-25675
An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.
Published 2024-02-09 · Modified
9.8EPSS 0.008
CVE-2024-29859
In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.
Published 2024-03-21 · Analyzed
9.8EPSS 0.008
CVE-2023-50918
app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.
Published 2023-12-15 · Modified
9.8EPSS 0.008
CVE-2024-25674
An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.
Published 2024-02-09 · Modified
9.8EPSS 0.008
CVE-2023-24028
In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.
Published 2023-01-20 · Modified
9.8EPSS 0.007
CVE-2024-46918
app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.
Published 2024-09-15 · Modified
9.8EPSS 0.004
CVE-2024-45509
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.
Published 2024-09-01 · Analyzed
9.8EPSS 0.004
CVE-2024-29858
In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.
Published 2024-03-21 · Analyzed
9.8EPSS 0.004
CVE-2026-39962
LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable
Published 2026-04-09 · Analyzed
9.6EPSS 0.007
CVE-2026-56423
MISP Core: Broken access control allows instance-wide unauthorized deletion of event reports and sharing groups via bulk deletion endpoints
Published 2026-06-22 · Analyzed
9.4EPSS 0.005
CVE-2026-44381
MISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listings
Published 2026-05-13 · Analyzed
9.3EPSS 0.008
CVE-2026-56447
MISP remote code execution via arbitrary rdkafka configuration path
Published 2026-06-22 · Analyzed
9.3EPSS 0.006
CVE-2026-56425
MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log Injection
Published 2026-06-22 · Analyzed
9.3EPSS 0.005
CVE-2021-25323
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.
Published 2021-01-19 · Modified
9.1EPSS 0.013
CVE-2026-86419
MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed Redirects and TAXII Discovery
Published 2026-09-07 · Analyzed
9.1EPSS 0.004
CVE-2026-85221
MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle Attacks
Published 2026-09-03 · Analyzed
9.1EPSS 0.003
CVE-2018-19908
An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious authenticated user to execute arbitrary commands by tweaking the original filename of the STIX import.
Published 2018-12-06 · Modified
9.01 PoCEPSS 0.173
CVE-2018-6926
In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.
Published 2018-02-12 · Modified
9.0EPSS 0.017
CVE-2025-67906
In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.
Published 2025-12-15 · Modified
9.0EPSS 0.003
CVE-2022-27245
An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.
Published 2022-03-18 · Modified
8.8EPSS 0.009
CVE-2026-56424
Broken access control in MISP core allows cross-organization unauthorized modification or deletion of analyst data, event reports, collections, templates, and decaying models
Published 2026-06-22 · Analyzed
8.8EPSS 0.005
CVE-2020-15711
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
Published 2020-07-14 · Modified
8.8EPSS 0.005
1 / 4Next →