misp-project records
141 published records for vendor misp-project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 7.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')49
- CWE-862 Missing Authorization8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-863 Incorrect Authorization6
- CWE-20 Improper Input Validation6
- CWE-639 Authorization Bypass Through User-Controlled Key4
The weakness classes this vendor ships most often: where to look.
CWEAll records
141 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-19908Proof of concept | An issue was discovered in MISP 2.4.9x before 2.4.99.misp-project · misp · CWE-78 | High8.8 | — | 17.3% | Dec 6, 2018 |
40Plan | CVE-2015-5721No exploit | Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialmisp-project · misp · CWE-94 | Critical9.8 | — | 2.6% | Sep 3, 2016 |
40Plan | CVE-2015-5719No exploit | app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames undmisp-project · misp | Critical9.8 | — | 2.3% | Sep 3, 2016 |
40Plan | CVE-2022-29528No exploit | An issue was discovered in MISP before 2.4.158.misp-project · misp · CWE-502 | Critical9.8 | — | 2.2% | Apr 20, 2022 |
40Plan | CVE-2021-41326No exploit | In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.misp-project · misp | Critical9.8 | — | 1.8% | Sep 17, 2021 |
39Monitor | CVE-2018-12649No exploit | An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92.misp-project · misp · CWE-307 | Critical9.8 | — | 1.5% | Jun 22, 2018 |
39Monitor | CVE-2020-15411No exploit | An issue was discovered in MISP 2.4.128.misp-project · misp | Critical9.8 | — | 1.5% | Jun 30, 2020 |
39Monitor | CVE-2022-48328No exploit | app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.misp-project · misp · CWE-755 | Critical9.8 | — | 1.3% | Feb 20, 2023 |
39Monitor | CVE-2020-29006No exploit | MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.misp-project · misp · CWE-862 | Critical9.8 | — | 1.3% | Nov 24, 2020 |
39Monitor | CVE-2021-35502No exploit | app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-tempmisp-project · misp | Critical9.8 | — | 1.1% | Jun 25, 2021 |
39Monitor | CVE-2021-39302No exploit | MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.misp-project · misp · CWE-89 | Critical9.8 | — | 0.9% | Aug 19, 2021 |
39Monitor | CVE-2022-48329No exploit | MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Mmisp-project · misp · CWE-755 | Critical9.8 | — | 0.9% | Feb 20, 2023 |
39Monitor | CVE-2023-48655No exploit | An issue was discovered in MISP before 2.4.176.misp-project · misp · CWE-116 | Critical9.8 | — | 0.9% | Nov 17, 2023 |
39Monitor | CVE-2023-48657No exploit | An issue was discovered in MISP before 2.4.176.misp-project · misp | Critical9.8 | — | 0.9% | Nov 17, 2023 |
39Monitor | CVE-2023-48656No exploit | An issue was discovered in MISP before 2.4.176.misp-project · misp | Critical9.8 | — | 0.9% | Nov 17, 2023 |
39Monitor | CVE-2023-48658No exploit | An issue was discovered in MISP before 2.4.176.misp-project · misp | Critical9.8 | — | 0.9% | Nov 17, 2023 |
39Monitor | CVE-2023-48659No exploit | An issue was discovered in MISP before 2.4.176.misp-project · misp | Critical9.8 | — | 0.9% | Nov 17, 2023 |
39Monitor | CVE-2024-25675No exploit | An issue was discovered in MISP before 2.4.184.misp-project · misp · CWE-749 | Critical9.8 | — | 0.8% | Feb 9, 2024 |
39Monitor | CVE-2024-29859No exploit | In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.misp-project · misp · CWE-434 | Critical9.8 | — | 0.8% | Mar 21, 2024 |
39Monitor | CVE-2023-50918No exploit | app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.misp-project · misp | Critical9.8 | — | 0.8% | Dec 15, 2023 |
39Monitor | CVE-2024-25674No exploit | An issue was discovered in MISP before 2.4.184.misp-project · misp · CWE-434 | Critical9.8 | — | 0.8% | Feb 9, 2024 |
39Monitor | CVE-2023-24028No exploit | In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.misp-project · misp · CWE-284 | Critical9.8 | — | 0.7% | Jan 20, 2023 |
39Monitor | CVE-2024-29858No exploit | In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.misp-project · misp · CWE-616 | Critical9.8 | — | 0.4% | Mar 21, 2024 |
38Monitor | CVE-2026-85216No exploit | MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentialsmisp-project · misp · CWE-521 | Critical9.5 | — | 0.9% | Sep 3, 2026 |
37Monitor | CVE-2026-44381Proof of concept | MISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listingsmisp-project · misp · CWE-89 | Critical9.3 | — | 0.8% | May 13, 2026 |
- CVE-2018-1990840Plan
An issue was discovered in MISP 2.4.9x before 2.4.99.
HighCVSS 8.8Proof of conceptEPSS 17%misp-project · mispDec 6, 2018
- CVE-2015-572140Plan
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serial
CriticalCVSS 9.8No exploitEPSS 3%misp-project · mispSep 3, 2016
- CVE-2015-571940Plan
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames und
CriticalCVSS 9.8No exploitEPSS 2%misp-project · mispSep 3, 2016
- CVE-2022-2952840Plan
An issue was discovered in MISP before 2.4.158.
CriticalCVSS 9.8No exploitEPSS 2%misp-project · mispApr 20, 2022
- CVE-2021-4132640Plan
In MISP before 2.4.148, app/Lib/Export/OpendataExport.php mishandles parameter data that is used in a shell_exec call.
CriticalCVSS 9.8No exploitEPSS 2%misp-project · mispSep 17, 2021
- CVE-2018-1264939Monitor
An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispJun 22, 2018
- CVE-2020-1541139Monitor
An issue was discovered in MISP 2.4.128.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispJun 30, 2020
- CVE-2022-4832839Monitor
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispFeb 20, 2023
- CVE-2020-2900639Monitor
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispNov 24, 2020
- CVE-2021-3550239Monitor
app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data related to generic-temp
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispJun 25, 2021
- CVE-2021-3930239Monitor
MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispAug 19, 2021
- CVE-2022-4832939Monitor
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/M
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispFeb 20, 2023
- CVE-2023-4865539Monitor
An issue was discovered in MISP before 2.4.176.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispNov 17, 2023
- CVE-2023-4865739Monitor
An issue was discovered in MISP before 2.4.176.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispNov 17, 2023
- CVE-2023-4865639Monitor
An issue was discovered in MISP before 2.4.176.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispNov 17, 2023
- CVE-2023-4865839Monitor
An issue was discovered in MISP before 2.4.176.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispNov 17, 2023
- CVE-2023-4865939Monitor
An issue was discovered in MISP before 2.4.176.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispNov 17, 2023
- CVE-2024-2567539Monitor
An issue was discovered in MISP before 2.4.184.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispFeb 9, 2024
- CVE-2024-2985939Monitor
In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispMar 21, 2024
- CVE-2023-5091839Monitor
app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispDec 15, 2023
- CVE-2024-2567439Monitor
An issue was discovered in MISP before 2.4.184.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispFeb 9, 2024
- CVE-2023-2402839Monitor
In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.
CriticalCVSS 9.8No exploitEPSS 1%misp-project · mispJan 20, 2023
- CVE-2024-2985839Monitor
In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.
CriticalCVSS 9.8No exploitEPSS 0%misp-project · mispMar 21, 2024
- CVE-2026-8521638Monitor
MISP LDAP and LinOTP Authentication Bypass via Empty or Invalid Credentials
CriticalCVSS 9.5No exploitEPSS 1%misp-project · mispSep 3, 2026
- CVE-2026-4438137Monitor
MISP: SQL injection via unvalidated ordering parameters in event and shadow attribute listings
CriticalCVSS 9.3Proof of conceptEPSS 1%misp-project · mispMay 13, 2026