Total
141 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2015-5720 | 1 Misp-project | 1 Misp | 2026-06-23 | 4.3 MEDIUM | 6.1 MEDIUM |
| Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edit.ctp, and (3) ajaxification.js. | |||||
| CVE-2023-28884 | 1 Misp-project | 1 Misp | 2026-06-23 | N/A | 6.1 MEDIUM |
| In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index. | |||||
| CVE-2023-48657 | 1 Misp-project | 1 Misp | 2026-06-23 | N/A | 9.8 CRITICAL |
| An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters. | |||||
| CVE-2023-24070 | 1 Misp-project | 1 Misp | 2026-06-23 | N/A | 6.1 MEDIUM |
| app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field. | |||||
| CVE-2022-42724 | 1 Misp-project | 1 Misp | 2026-06-23 | N/A | 4.3 MEDIUM |
| app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have). | |||||
| CVE-2023-37306 | 1 Misp-project | 1 Misp | 2026-06-23 | N/A | 7.5 HIGH |
| MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages. | |||||
| CVE-2023-37307 | 1 Misp-project | 1 Misp | 2026-06-23 | N/A | 5.4 MEDIUM |
| In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts. | |||||
| CVE-2023-48656 | 1 Misp-project | 1 Misp | 2026-06-23 | N/A | 9.8 CRITICAL |
| An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses. | |||||
| CVE-2023-48655 | 1 Misp-project | 1 Misp | 2026-06-23 | N/A | 9.8 CRITICAL |
| An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters. | |||||
| CVE-2022-47928 | 1 Misp-project | 1 Misp | 2026-06-23 | N/A | 6.1 MEDIUM |
| In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp. | |||||
| CVE-2015-5719 | 1 Misp-project | 1 Misp | 2026-06-23 | 10.0 HIGH | 9.8 CRITICAL |
| app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors. | |||||
| CVE-2023-50918 | 1 Misp-project | 1 Misp | 2026-06-22 | N/A | 9.8 CRITICAL |
| app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs. | |||||
| CVE-2020-13153 | 1 Misp-project | 1 Misp | 2026-06-22 | 4.3 MEDIUM | 6.1 MEDIUM |
| app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view. | |||||
| CVE-2020-28947 | 1 Misp-project | 1 Misp | 2026-06-22 | 4.3 MEDIUM | 6.1 MEDIUM |
| In MISP 2.4.134, XSS exists in the template element index view because the id parameter is mishandled. | |||||
| CVE-2019-12794 | 1 Misp-project | 1 Misp | 2026-06-22 | 6.0 MEDIUM | 6.6 MEDIUM |
| An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability to reset passwords for all of their organization's users). This, however, could be abused in a situation where the host organization of an instance creates organization admins. An organization admin could set a password manually for the site admin or simply use the API key of the site admin to impersonate them. The potential for abuse only occurs when the host organization creates lower-privilege organization admins instead of the usual site admins. Also, only organization admins of the same organization as the site admin could abuse this. | |||||
| CVE-2019-16202 | 1 Misp-project | 1 Misp | 2026-06-22 | 4.0 MEDIUM | 6.5 MEDIUM |
| MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This could be an indication of an attempted privilege escalation on older vulnerable versions of MISP (<2.4.115)" message. | |||||
| CVE-2020-8894 | 1 Misp-project | 1 Misp | 2026-06-22 | 6.4 MEDIUM | 6.5 MEDIUM |
| An issue was discovered in MISP before 2.4.121. ACLs for discussion threads were mishandled in app/Controller/ThreadsController.php and app/Model/Thread.php. | |||||
| CVE-2022-29532 | 1 Misp-project | 1 Misp | 2026-06-22 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it. | |||||
| CVE-2020-29006 | 1 Misp-project | 1 Misp | 2026-06-22 | 7.5 HIGH | 9.8 CRITICAL |
| MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php. | |||||
| CVE-2023-49926 | 1 Misp-project | 1 Misp | 2026-06-22 | N/A | 6.1 MEDIUM |
| app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget. | |||||
