VendorsMISP-Projectmispany version
Vulnerabilities

MISP-Project MISP Project MISP (Malware Information Sharing Platform) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

105CVEs
CVE-2018-8949
An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API integrity bug, potentially allowing users to delete attributes of other events. A crafted edit for an event (without attribute UUIDs but attribute IDs set) could overwrite an existing attribute.
Published 2018-03-23 · Modified
5.5EPSS 0.007
CVE-2021-27904
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, the "all org" flag sometimes provided view access to unintended actors.
Published 2021-03-02 · Modified
5.5EPSS 0.003
CVE-2024-58129
In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.
Published 2025-03-28 · Analyzed
5.5EPSS 0.002
CVE-2024-58128
In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.
Published 2025-03-28 · Analyzed
5.5EPSS 0.002
CVE-2022-29529
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
Published 2022-04-20 · Modified
5.4EPSS 0.008
CVE-2022-29531
An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.
Published 2022-04-20 · Modified
5.4EPSS 0.008
CVE-2022-29530
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
Published 2022-04-20 · Modified
5.4EPSS 0.008
CVE-2023-37307
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
Published 2023-06-30 · Modified
5.4EPSS 0.005
CVE-2026-85230
MISP Dashboard Button Widget Allows Persistent JavaScript URL Injection
Published 2026-09-03 · Analyzed
5.4EPSS 0.003
CVE-2026-86440
MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs
Published 2026-09-07 · Analyzed
5.4EPSS 0.002
CVE-2026-86342
MISP Freetext Feed Preview Improper Authorization Exposes Restricted Event and Feed Information
Published 2026-09-07 · Analyzed
5.3EPSS 0.003
CVE-2026-44379
MISP: Improper UUID validation in MISP Collections
Published 2026-05-13 · Analyzed
5.3EPSS 0.003
CVE-2026-86451
MISP Event Graph Object Reference Lookup Exposes References from Unauthorized Objects
Published 2026-09-07 · Analyzed
5.3EPSS 0.003
CVE-2026-86417
MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized Users
Published 2026-09-07 · Analyzed
5.3EPSS 0.003
CVE-2026-85226
MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted Correlations
Published 2026-09-03 · Analyzed
5.3EPSS 0.003
CVE-2026-10854
Unauthorized exposure of private galaxies in MISP event template creation
Published 2026-06-04 · Analyzed
5.3EPSS 0.002
CVE-2026-10864
MISP Dashboard widget field selection may expose restricted user and organisation data
Published 2026-06-04 · Analyzed
5.3EPSS 0.002
CVE-2026-10855
MISP Event template importer authorization bypass
Published 2026-06-04 · Analyzed
5.1EPSS 0.002
CVE-2020-11458
app/Model/feed.php in MISP before 2.4.124 allows administrators to choose arbitrary files that should be ingested by MISP. This does not cause a leak of the full contents of a file, but does cause a leaks of strings that match certain patterns. Among the data that can leak are passwords from database.php or GPG key passphrases from config.php.
Published 2020-04-02 · Modified
4.9EPSS 0.011
CVE-2022-29532
An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.
Published 2022-04-20 · Modified
4.8EPSS 0.008
CVE-2022-27244
An issue was discovered in MISP before 2.4.156. A malicious site administrator could store an XSS payload in the custom auth name. This would be executed each time the administrator modifies a user.
Published 2022-03-18 · Modified
4.8EPSS 0.005
CVE-2022-42724
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).
Published 2022-10-10 · Modified
4.3EPSS 0.005
CVE-2026-86441
MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidden Organisation Data
Published 2026-09-07 · Analyzed
4.3EPSS 0.003
CVE-2026-86418
MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized Users
Published 2026-09-07 · Modified
4.3EPSS 0.003
CVE-2024-57969
app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.
Published 2025-02-14 · Analyzed
4.3EPSS 0.003
← Prev3 / 3