VendorsMISP-Projectmispall versions
Vulnerabilities

MISP-Project MISP Project MISP (Malware Information Sharing Platform)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

141CVEs
CVE-2026-85230
MISP Dashboard Button Widget Allows Persistent JavaScript URL Injection
Published 2026-09-03 · Analyzed
5.4EPSS 0.003
CVE-2026-86440
MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLs
Published 2026-09-07 · Analyzed
5.4EPSS 0.002
CVE-2019-19379
In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.
Published 2019-11-28 · Modified
5.3EPSS 0.011
CVE-2019-9482
In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only).
Published 2019-03-01 · Modified
5.3EPSS 0.007
CVE-2026-86342
MISP Freetext Feed Preview Improper Authorization Exposes Restricted Event and Feed Information
Published 2026-09-07 · Analyzed
5.3EPSS 0.003
CVE-2026-44379
MISP: Improper UUID validation in MISP Collections
Published 2026-05-13 · Analyzed
5.3EPSS 0.003
CVE-2026-86451
MISP Event Graph Object Reference Lookup Exposes References from Unauthorized Objects
Published 2026-09-07 · Analyzed
5.3EPSS 0.003
CVE-2026-86417
MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Unauthorized Users
Published 2026-09-07 · Analyzed
5.3EPSS 0.003
CVE-2026-85226
MISP OnDemand Correlation Engine Missing Access Control Allows Disclosure of Restricted Correlations
Published 2026-09-03 · Analyzed
5.3EPSS 0.003
CVE-2026-10864
MISP Dashboard widget field selection may expose restricted user and organisation data
Published 2026-06-04 · Analyzed
5.3EPSS 0.002
CVE-2026-10854
Unauthorized exposure of private galaxies in MISP event template creation
Published 2026-06-04 · Analyzed
5.3EPSS 0.002
CVE-2026-10855
MISP Event template importer authorization bypass
Published 2026-06-04 · Analyzed
5.1EPSS 0.002
CVE-2020-11458
app/Model/feed.php in MISP before 2.4.124 allows administrators to choose arbitrary files that should be ingested by MISP. This does not cause a leak of the full contents of a file, but does cause a leaks of strings that match certain patterns. Among the data that can leak are passwords from database.php or GPG key passphrases from config.php.
Published 2020-04-02 · Modified
4.9EPSS 0.011
CVE-2017-16946
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.
Published 2017-11-25 · Modified
4.9EPSS 0.011
CVE-2022-29532
An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.
Published 2022-04-20 · Modified
4.8EPSS 0.008
CVE-2022-27244
An issue was discovered in MISP before 2.4.156. A malicious site administrator could store an XSS payload in the custom auth name. This would be executed each time the administrator modifies a user.
Published 2022-03-18 · Modified
4.8EPSS 0.005
CVE-2020-15412
An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.
Published 2020-06-30 · Modified
4.3EPSS 0.007
CVE-2022-42724
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).
Published 2022-10-10 · Modified
4.3EPSS 0.005
CVE-2026-86441
MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions and Expose Hidden Organisation Data
Published 2026-09-07 · Analyzed
4.3EPSS 0.003
CVE-2026-86418
MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Unauthorized Users
Published 2026-09-07 · Modified
4.3EPSS 0.003
CVE-2024-57969
app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.
Published 2025-02-14 · Analyzed
4.3EPSS 0.003
← Prev4 / 4