MISP / MISP
167 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-104914 | MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View | MEDIUM | 5.3 | Oct 2, 2026 |
| CVE-2026-104912 | MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data | HIGH | 7.1 | Oct 2, 2026 |
| CVE-2026-104910 | MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization | MEDIUM | 5.3 | Oct 2, 2026 |
| CVE-2026-104908 | MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging | HIGH | 7.1 | Oct 2, 2026 |
| CVE-2026-104907 | MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler | MEDIUM | 4.8 | Oct 2, 2026 |
| CVE-2026-104906 | MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output | MEDIUM | 6.2 | Oct 2, 2026 |
| CVE-2026-104901 | MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server | MEDIUM | 5.1 | Oct 2, 2026 |
| CVE-2026-104900 | MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index | MEDIUM | 5.3 | Oct 2, 2026 |
| CVE-2026-103858 | MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions | MEDIUM | 5.3 | Oct 1, 2026 |
| CVE-2026-103664 | MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter | MEDIUM | 4.8 | Oct 1, 2026 |
| CVE-2026-103662 | MISP Reflected XSS in Taxonomy Tag Confirmation Forms | MEDIUM | 5.1 | Oct 1, 2026 |
| CVE-2026-103659 | MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attributes | HIGH | 7.1 | Oct 1, 2026 |
| CVE-2026-103655 | MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period | CRITICAL | 9.3 | Oct 1, 2026 |
| CVE-2026-103651 | MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass | HIGH | 7.6 | Oct 1, 2026 |
| CVE-2026-103389 | MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph | MEDIUM | 6.2 | Sep 30, 2026 |
| CVE-2026-103388 | MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field | MEDIUM | 6.2 | Sep 30, 2026 |
| CVE-2026-103321 | MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image | HIGH | 8.3 | Sep 30, 2026 |
| CVE-2026-103239 | MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection | HIGH | 8.6 | Sep 30, 2026 |
| CVE-2026-103237 | MISP: Nested Model Alias Key Bypasses Sanitization to Modify Cross-Tenant Rows | HIGH | 8.3 | Sep 30, 2026 |
| CVE-2026-103235 | MISP Event Delegation Mass Assignment Allows Retargeting Delegation to Arbitrary Events | HIGH | 8.7 | Sep 30, 2026 |
| CVE-2026-95806 | MISP: PHP phar stream wrapper enables deserialization and code execution via caller-influenced filesystem paths | HIGH | 7.7 | Sep 22, 2026 |
| CVE-2026-95805 | MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restriction | MEDIUM | 5.3 | Sep 22, 2026 |
| CVE-2026-95754 | MISP: Disabled-user check ineffective in pre-authentication TOTP login branch | MEDIUM | 6.9 | Sep 22, 2026 |
| CVE-2026-95703 | MISP OrganisationsController File Existence and Image-Type Oracle via Forged Upload tmp_name | MEDIUM | 5.1 | Sep 22, 2026 |
| CVE-2026-95701 | MISP Path Traversal via Organization Name in Org-Statistics Logo Check | MEDIUM | 5.1 | Sep 22, 2026 |
Showing 1 to 25 of 167 CVEs