← All vendors

misp-project

30 known vulnerabilities affecting misp-project products.

Products

misp 30

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-85216 Medium 0.5% 9.8 MISP contains an authentication bypass vulnerability in its LDAP and LinOTP auth…
CVE-2026-9137 Medium 0.4% 7.5 The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but…
CVE-2026-10611 Medium 0.4% 10.0 An authentication bypass vulnerability exists in MISP when LDAP mixed authentica…
CVE-2026-86452 Medium 0.3% 7.5 Affected versions of MISP permit unauthenticated or weakly constrained request p…
CVE-2026-85237 Medium 0.3% 8.1 A vulnerability in MISP's email-based one-time password (OTP) authentication flo…
CVE-2026-86419 Medium 0.2% 9.1 Affected versions of MISP contain insufficient validation of server-side outboun…
CVE-2026-10863 Medium 0.2% 8.1 A security issue was fixed in the correlations over-correlation endpoint where t…
CVE-2026-85236 Medium 0.2% 8.8 A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents…
CVE-2026-85221 Medium 0.1% 9.1 MISP contains an improper TLS certificate validation vulnerability in CurlClient…
CVE-2026-86347 Low 0.3% 6.5 Affected versions of MISP allow any authenticated user to access TemplatesContro…
CVE-2026-85239 Low 0.3% 6.5 A vulnerability in MISP's event template handling allowed an authenticated user …
CVE-2026-9136 Low 0.2% 6.5 A vulnerability was identified in the ShadowAttribute proposal creation workflow…
CVE-2026-10861 Low 0.2% 6.1 An open redirect vulnerability existed in MISP UsersController::routeafterlogin(…
CVE-2026-85238 Low 0.2% 6.8 MISP contains a session fixation vulnerability in the CustomAuth authentication …
CVE-2026-86342 Low 0.2% 4.3 Affected versions of MISP contain improper authorization checks in the freetext …
CVE-2026-86408 Low 0.2% 6.5 Affected versions of MISP do not enforce parent-event visibility when serving cr…
CVE-2026-10860 Low 0.2% 6.5 A logic error in the MISP CRUD component delete handler allowed validation failu…
CVE-2026-86351 Low 0.2% 6.1 Affected versions of MISP validate the user-configurable homepage by checking on…
CVE-2026-10854 Low 0.2% 4.3 A visibility control issue in the event template creation workflow allowed non-s…
CVE-2026-10864 Low 0.2% 4.3 A vulnerability in the MISP dashboard widgets allowed an authenticated user to m…
CVE-2026-86451 Low 0.2% 4.3 Affected versions of MISP allow authenticated users to retrieve object-reference…
CVE-2026-85230 Low 0.2% 5.4 A persistent unsafe URL injection vulnerability exists in the MISP dashboard But…
CVE-2026-86441 Low 0.2% 4.3 Affected versions of MISP contain inconsistent authorization checks across dashb…
CVE-2026-86417 Low 0.2% 4.3 Affected versions of MISP inconsistently enforced email-address visibility in Da…
CVE-2026-86418 Low 0.2% 4.3 Affected versions of MISP expose organisation metadata through the dashboard org…
CVE-2026-85227 Low 0.2% 6.1 MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event …
CVE-2026-10855 Low 0.2% 4.3 An authorization flaw existed in the MISP Event Template Importer overwrite work…
CVE-2026-85226 Low 0.2% 4.3 MISP contains an authorization flaw in the OnDemand correlation engine where cor…
CVE-2026-10856 Low 0.1% 6.1 A URL validation flaw in the MISP dashboard button widget allowed a crafted rela…
CVE-2026-86440 Low 0.1% 5.4 Affected versions of MISP insufficiently validate URLs used by dashboard widgets…