VendorsMISP-Projectmispall versions
Vulnerabilities

MISP-Project MISP Project MISP (Malware Information Sharing Platform)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

141CVEs
CVE-2019-11812
A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be included in the discussion interface, and can be triggered by clicking on the link.
Published 2019-05-08 · Modified
6.1EPSS 0.008
CVE-2019-11814
An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in titles, as demonstrated by a screenshot.
Published 2019-05-08 · Modified
6.1EPSS 0.008
CVE-2019-14286
In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user toggles the event graph view. A malicious MISP event must be crafted in order to trigger the vulnerability.
Published 2019-07-27 · Modified
6.1EPSS 0.008
CVE-2018-11562
An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter.
Published 2018-05-30 · Modified
6.1EPSS 0.008
CVE-2019-11813
An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS via link type attributes with javascript:// links.
Published 2019-05-08 · Modified
6.1EPSS 0.008
CVE-2021-25324
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
Published 2021-01-19 · Modified
6.1EPSS 0.008
CVE-2021-25325
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.
Published 2021-01-19 · Modified
6.1EPSS 0.008
CVE-2018-8948
In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.
Published 2018-03-23 · Modified
6.1EPSS 0.008
CVE-2020-29572
app/View/Elements/genericElements/SingleViews/Fields/genericField.ctp in MISP 2.4.135 has XSS via the authkey comment field.
Published 2020-12-05 · Modified
6.1EPSS 0.008
CVE-2021-3184
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
Published 2021-01-19 · Modified
6.1EPSS 0.008
CVE-2021-36212
app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.
Published 2021-07-07 · Modified
6.1EPSS 0.006
CVE-2022-27246
An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default.
Published 2022-03-18 · Modified
6.1EPSS 0.006
CVE-2023-40224
MISP 2.4.174 allows XSS in app/View/Events/index.ctp.
Published 2023-08-10 · Modified
6.1EPSS 0.004
CVE-2023-41098
An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit.
Published 2023-08-23 · Modified
6.1EPSS 0.004
CVE-2022-47928
In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
Published 2022-12-22 · Modified
6.1EPSS 0.004
CVE-2023-49926
app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.
Published 2023-12-03 · Modified
6.1EPSS 0.004
CVE-2023-28884
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
Published 2023-03-27 · Modified
6.1EPSS 0.004
CVE-2023-24070
app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
Published 2023-01-23 · Modified
6.1EPSS 0.004
CVE-2023-24027
In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
Published 2023-01-20 · Modified
6.1EPSS 0.004
CVE-2023-24026
In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.
Published 2023-01-20 · Modified
6.1EPSS 0.004
CVE-2023-28606
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
Published 2023-03-18 · Modified
6.1EPSS 0.004
CVE-2023-28607
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
Published 2023-03-18 · Modified
6.1EPSS 0.004
CVE-2026-86351
MISP User Homepage Validation Allows Authenticated Open Redirect via Protocol-Relative URL
Published 2026-09-07 · Analyzed
6.1EPSS 0.003
CVE-2026-85227
Reflected Cross-Site Scripting in MISP Event Filtering via taggedAttributes and galaxyAttachedAttributes Parameters
Published 2026-09-03 · Analyzed
6.1EPSS 0.003
CVE-2026-10861
MISP post-login open redirect via pre_login_requested_url
Published 2026-06-04 · Analyzed
6.1EPSS 0.002
CVE-2026-10856
Open redirect in MISP dashboard button widget URL handling
Published 2026-06-04 · Analyzed
6.1EPSS 0.001
CVE-2020-8891
An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.
Published 2020-02-11 · Modified
5.9EPSS 0.014
CVE-2020-8890
An issue was discovered in MISP before 2.4.121. It mishandled time skew (between the machine hosting the web server and the machine hosting the database) when trying to block a brute-force series of invalid requests.
Published 2020-02-11 · Modified
5.9EPSS 0.011
CVE-2018-8949
An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attribute UUIDs but attribute IDs set) could overwrite an existing attribute.
Published 2018-03-23 · Modified
5.5EPSS 0.007
CVE-2021-27904
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.
Published 2021-03-02 · Modified
5.5EPSS 0.003
CVE-2024-58128
In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.
Published 2025-03-28 · Analyzed
5.5EPSS 0.002
CVE-2024-58129
In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.
Published 2025-03-28 · Analyzed
5.5EPSS 0.002
CVE-2022-29529
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
Published 2022-04-20 · Modified
5.4EPSS 0.008
CVE-2022-29530
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
Published 2022-04-20 · Modified
5.4EPSS 0.008
CVE-2022-29531
An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.
Published 2022-04-20 · Modified
5.4EPSS 0.008
CVE-2021-37743
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.
Published 2021-07-30 · Modified
5.4EPSS 0.007
CVE-2017-16802
In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.
Published 2017-11-13 · Modified
5.4EPSS 0.006
CVE-2021-37742
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.
Published 2021-07-30 · Modified
5.4EPSS 0.006
CVE-2021-37534
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
Published 2021-07-26 · Modified
5.4EPSS 0.005
CVE-2023-37307
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
Published 2023-06-30 · Modified
5.4EPSS 0.005
← Prev3 / 4Next →