MISP
92 known vulnerabilities in MISP, 3 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-104914 CVSS 5.3 medium MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries…
- CVE-2026-104912 CVSS 7.1 high MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that…
- CVE-2026-104910 CVSS 5.3 medium MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a…
- CVE-2026-104908 CVSS 7.1 high MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to…
- CVE-2026-104907 CVSS 4.8 medium MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is…
- CVE-2026-104906 CVSS 6.2 medium MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON…
- CVE-2026-104901 CVSS 5.1 medium MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the…
- CVE-2026-104900 CVSS 5.3 medium MISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field…
- CVE-2026-103858 CVSS 5.3 medium MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies…
- CVE-2026-103664 CVSS 4.8 medium MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by…
- CVE-2026-103662 CVSS 5.1 medium MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and…
- CVE-2026-103659 CVSS 7.1 high MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the…
- CVE-2026-103655 CVSS 9.3 critical MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be…
- CVE-2026-103651 CVSS 7.6 high MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and…
- CVE-2026-103389 CVSS 6.2 medium MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was…
- CVE-2026-103388 CVSS 6.2 medium MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL…
- CVE-2026-103321 CVSS 8.3 high MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was…
- CVE-2026-103239 CVSS 8.6 high MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted…
- CVE-2026-103237 CVSS 8.3 high MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints…
- CVE-2026-103235 CVSS 8.7 high MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation…
- CVE-2026-95806 CVSS 7.7 high MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper…
- CVE-2026-95805 CVSS 5.3 medium A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the…
- CVE-2026-95754 CVSS 6.9 medium In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification…
- CVE-2026-95703 CVSS 5.1 medium In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists…
- CVE-2026-95701 CVSS 5.1 medium In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when…
- CVE-2026-95698 CVSS 5.3 medium The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organization identifier with…
- CVE-2026-95697 CVSS 5.3 medium MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method…
- CVE-2026-95693 CVSS 5.3 medium In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists()…
- CVE-2026-95685 CVSS 5.3 medium MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of…
- CVE-2026-95683 CVSS 5.3 medium In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrichment logic fetched…