VendorsMISP-Projectmispall versions
Vulnerabilities

MISP-Project MISP Project MISP (Malware Information Sharing Platform)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

141CVEs
CVE-2026-85236
MISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET Request
Published 2026-09-03 · Analyzed
8.8EPSS 0.003
CVE-2026-56446
Authenticated Remote Code Execution via Arbitrary NDJSON Error Log Path in MISP
Published 2026-06-22 · Analyzed
8.7EPSS 0.007
CVE-2026-86452
MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request Flooding
Published 2026-09-07 · Modified
8.7EPSS 0.005
CVE-2026-44380
MISP: Improper access control in auth key reset allows privilege escalation to site administrator
Published 2026-05-13 · Analyzed
8.6EPSS 0.006
CVE-2026-85237
Missing Rate Limiting in Email OTP Verification Allows Brute-Force Authentication Bypass
Published 2026-09-03 · Analyzed
8.6EPSS 0.005
CVE-2026-9136
Unauthorized ShadowAttribute modification in MISP via client-supplied identifier
Published 2026-05-20 · Analyzed
8.3EPSS 0.003
CVE-2020-8892
An issue was discovered in MISP before 2.4.121. It did not consider the HTTP PUT method when trying to block a brute-force series of invalid requests.
Published 2020-02-11 · Modified
8.1EPSS 0.017
CVE-2017-14337
When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST API, if an external user provides X.509 certificate authentication and this API returns an empty value, the unauthenticated user can be granted access as an arbitrary user.
Published 2017-09-12 · Modified
8.1EPSS 0.009
CVE-2026-10863
MISP User-controlled order parameter in correlations over-correlation endpoint
Published 2026-06-04 · Analyzed
8.1EPSS 0.002
CVE-2026-10860
MISP CRUDComponent delete validation bypass via operator precedence error
Published 2026-06-04 · Analyzed
7.9EPSS 0.002
CVE-2022-27243
An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom terms file setting.
Published 2022-03-18 · Modified
7.8EPSS 0.012
CVE-2026-85238
Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking
Published 2026-09-03 · Analyzed
7.6EPSS 0.003
CVE-2020-8893
An issue was discovered in MISP before 2.4.121. The Galaxy view contained an incorrectly sanitized search string in app/View/Galaxies/view.ctp.
Published 2020-02-11 · Modified
7.5EPSS 0.021
CVE-2022-29534
An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.
Published 2022-04-20 · Modified
7.5EPSS 0.016
CVE-2020-28043
MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.
Published 2020-11-01 · Modified
7.5EPSS 0.013
CVE-2020-14969
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.
Published 2020-06-22 · Modified
7.5EPSS 0.013
CVE-2020-25766
An issue was discovered in MISP before 2.4.132. It can perform an unwanted action because of a POST operation on a form that is not linked to the login page.
Published 2020-09-18 · Modified
7.5EPSS 0.012
CVE-2021-31780
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is reused.
Published 2021-04-23 · Modified
7.5EPSS 0.010
CVE-2023-37306
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
Published 2023-06-30 · Modified
7.5EPSS 0.005
CVE-2026-9137
CSP Report Endpoint Log Flooding in MISP via Incorrect Size Limit
Published 2026-05-20 · Analyzed
7.5EPSS 0.005
CVE-2019-12868
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.
Published 2019-06-17 · Modified
7.2EPSS 0.063
CVE-2024-58130
In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.
Published 2025-03-28 · Analyzed
7.2EPSS 0.002
CVE-2026-85239
MISP Event Template Definition Validation Bypass Allows Persistent Denial of Service
Published 2026-09-03 · Analyzed
7.1EPSS 0.004
CVE-2026-86347
MISP Missing Authorization on Template File Upload Allows Authenticated Disk Exhaustion
Published 2026-09-07 · Analyzed
7.1EPSS 0.004
CVE-2026-86408
MISP Missing Authorization in Cryptographic Key View Exposes Signing Keys from Protected Events
Published 2026-09-07 · Analyzed
7.1EPSS 0.003
CVE-2026-8080
MISP core - Stored XSS in MISP template (old engine) element attribute type
Published 2026-05-07 · Analyzed
6.8EPSS 0.002
CVE-2019-12794
An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability to reset passwords for all of their organization's users). This, however, could be abused in a situation where the host organization of an instance creates organization admins. An organization admin could set a password manually for the site admin or simply use the API key of the site admin to impersonate them. The potential for abuse only occurs when the host organization creates lower-privilege organization admins instead of the usual site admins. Also, only organization admins of the same organization as the site admin could abuse this.
Published 2019-06-11 · Modified
6.6EPSS 0.009
CVE-2020-8894
An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsController.php and app/Model/Thread.php.
Published 2020-02-11 · Modified
6.5EPSS 0.014
CVE-2019-16202
MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP (<2.4.115)" message.
Published 2019-09-10 · Modified
6.5EPSS 0.013
CVE-2015-5720
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edit.ctp, and (3) ajaxification.js.
Published 2016-09-03 · Modified
6.1EPSS 0.014
CVE-2017-13671
app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.
Published 2017-08-24 · Modified
6.1EPSS 0.010
CVE-2019-10254
In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability.
Published 2019-03-28 · Modified
6.1EPSS 0.009
CVE-2020-10246
MISP 2.4.122 has reflected XSS via unsanitized URL parameters. This is related to app/View/Users/statistics_orgs.ctp.
Published 2020-03-09 · Modified
6.1EPSS 0.009
CVE-2020-10247
MISP 2.4.122 has Persistent XSS in the sighting popover tool. This is related to app/View/Elements/Events/View/sighting_field.ctp.
Published 2020-03-09 · Modified
6.1EPSS 0.009
CVE-2017-15216
MISP before 2.4.81 has a potential reflected XSS in a quickDelete action that is used to delete a sighting, related to app/View/Sightings/ajax/quickDeleteConfirmationForm.ctp and app/webroot/js/misp.js.
Published 2017-10-10 · Modified
6.1EPSS 0.008
CVE-2020-13153
app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.
Published 2020-05-18 · Modified
6.1EPSS 0.008
CVE-2022-29533
An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page."
Published 2022-04-20 · Modified
6.1EPSS 0.008
CVE-2018-11245
app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes.
Published 2018-05-18 · Modified
6.1EPSS 0.008
CVE-2020-24085
A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious JavaScript code.
Published 2021-01-20 · Modified
6.1EPSS 0.008
CVE-2020-28947
In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled.
Published 2020-11-19 · Modified
6.1EPSS 0.008
← Prev2 / 4Next →