VendorsMISP-Projectmispany version
Vulnerabilities

MISP-Project MISP Project MISP (Malware Information Sharing Platform) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

105CVEs
CVE-2015-5719
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.
Published 2016-09-03 · Modified
10.0EPSS 0.023
CVE-2026-10611
OTP bypass via plugin-based LDAP authentication in MISP when LDAP mixed authentication is enabled
Published 2026-06-02 · Analyzed
10.0EPSS 0.004
CVE-2015-5721
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.
Published 2016-09-03 · Modified
9.8EPSS 0.026
CVE-2022-29528
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
Published 2022-04-20 · Modified
9.8EPSS 0.022
CVE-2021-41326
In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.
Published 2021-09-17 · Modified
9.8EPSS 0.018
CVE-2022-48328
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
Published 2023-02-20 · Modified
9.8EPSS 0.013
CVE-2020-29006
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
Published 2020-11-24 · Modified
9.8EPSS 0.013
CVE-2022-48329
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
Published 2023-02-20 · Modified
9.8EPSS 0.009
CVE-2023-48655
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
Published 2023-11-17 · Modified
9.8EPSS 0.009
CVE-2023-48659
An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
Published 2023-11-17 · Modified
9.8EPSS 0.009
CVE-2023-48658
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.
Published 2023-11-17 · Modified
9.8EPSS 0.009
CVE-2023-48657
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
Published 2023-11-17 · Modified
9.8EPSS 0.009
CVE-2023-48656
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
Published 2023-11-17 · Modified
9.8EPSS 0.009
CVE-2026-85216
MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials
Published 2026-09-03 · Analyzed
9.8EPSS 0.009
CVE-2024-25675
An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.
Published 2024-02-09 · Modified
9.8EPSS 0.008
CVE-2024-29859
In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.
Published 2024-03-21 · Analyzed
9.8EPSS 0.008
CVE-2023-50918
app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.
Published 2023-12-15 · Modified
9.8EPSS 0.008
CVE-2024-25674
An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.
Published 2024-02-09 · Modified
9.8EPSS 0.008
CVE-2024-46918
app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.
Published 2024-09-15 · Modified
9.8EPSS 0.004
CVE-2024-45509
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.
Published 2024-09-01 · Analyzed
9.8EPSS 0.004
CVE-2024-29858
In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.
Published 2024-03-21 · Analyzed
9.8EPSS 0.004
CVE-2026-39962
LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable
Published 2026-04-09 · Analyzed
9.6EPSS 0.007
CVE-2026-56423
MISP Core: Broken access control allows instance-wide unauthorized deletion of event reports and sharing groups via bulk deletion endpoints
Published 2026-06-22 · Analyzed
9.4EPSS 0.005
CVE-2026-44381
MISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listings
Published 2026-05-13 · Analyzed
9.3EPSS 0.008
CVE-2026-56447
MISP remote code execution via arbitrary rdkafka configuration path
Published 2026-06-22 · Analyzed
9.3EPSS 0.006
CVE-2026-56425
MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log Injection
Published 2026-06-22 · Analyzed
9.3EPSS 0.005
CVE-2026-86419
MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed Redirects and TAXII Discovery
Published 2026-09-07 · Analyzed
9.1EPSS 0.004
CVE-2026-85221
MISP CurlClient TLS Peer Verification Disabled by Default Enables Man-in-the-Middle Attacks
Published 2026-09-03 · Analyzed
9.1EPSS 0.003
CVE-2018-19908
An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious authenticated user to execute arbitrary commands by tweaking the original filename of the STIX import.
Published 2018-12-06 · Modified
9.01 PoCEPSS 0.173
CVE-2025-67906
In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.
Published 2025-12-15 · Modified
9.0EPSS 0.003
CVE-2022-27245
An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.
Published 2022-03-18 · Modified
8.8EPSS 0.009
CVE-2026-56424
Broken access control in MISP core allows cross-organization unauthorized modification or deletion of analyst data, event reports, collections, templates, and decaying models
Published 2026-06-22 · Analyzed
8.8EPSS 0.005
CVE-2020-15711
In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.
Published 2020-07-14 · Modified
8.8EPSS 0.005
CVE-2026-85236
MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request
Published 2026-09-03 · Analyzed
8.8EPSS 0.003
CVE-2026-56446
Authenticated Remote Code Execution via Arbitrary NDJSON Error Log Path in MISP
Published 2026-06-22 · Analyzed
8.7EPSS 0.007
CVE-2026-86452
MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request Flooding
Published 2026-09-07 · Modified
8.7EPSS 0.005
CVE-2026-44380
MISP: Improper access control in auth key reset allows privilege escalation to site administrator
Published 2026-05-13 · Analyzed
8.6EPSS 0.006
CVE-2026-85237
Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass
Published 2026-09-03 · Analyzed
8.6EPSS 0.005
CVE-2026-9136
Unauthorized ShadowAttribute modification in MISP via client-supplied identifier
Published 2026-05-20 · Analyzed
8.3EPSS 0.003
CVE-2020-8892
An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-force series of invalid requests.
Published 2020-02-11 · Modified
8.1EPSS 0.017
1 / 3Next →