← Back

Misp

misp

Vendor: Misp Project • 122 CVEs

CVEs (122)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Misp Project
2Malware Information Sharing Platform
Misp
Jun 23, 2026
Jun 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
1Misp Project
2Malware Information Sharing Platform
Misp
Jun 23, 2026
Jun 30, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
1Misp Project
2Malware Information Sharing Platform
Misp
Jun 23, 2026
Mar 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
1Misp Project
2Malware Information Sharing Platform
Misp
Jun 23, 2026
Mar 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
1Misp Project
2Malware Information Sharing Platform
Misp
Jun 23, 2026
Mar 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Feb 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Feb 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
1Misp Project
2Malware Information Sharing Platform
Misp
Jun 23, 2026
Jan 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
1Misp Project
1Misp
Jun 17, 2026
Jan 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
1Misp Project
1Misp
Jun 17, 2026
Jan 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.
1Misp Project
2Malware Information Sharing Platform
Misp
Jun 23, 2026
Dec 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
1Misp Project
2Malware Information Sharing Platform
Misp
Jun 23, 2026
Oct 10, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Apr 20, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Apr 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page."
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Apr 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Apr 20, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Apr 20, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Apr 20, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Apr 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.