Search
Search Results (52 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-8080 | 2 Misp, Misp-project | 2 Misp, Misp | 2026-05-11 | 5.4 Medium |
| Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue affects MISP before 2.5.37. A stored cross-site scripting vulnerability exists in the template element attribute handling logic. The application accepted arbitrary values for the TemplateElementAttribute type and category fields without validating them against the known MISP attribute type and category definitions. An attacker with permission to create or modify template element attributes could store a crafted type value. This affects the old templating (not more accessible in 2.5.37) engine from MISP which will be removed in 2.5.38 | ||||
| CVE-2026-39962 | 2 Misp, Misp-project | 2 Misp, Misp | 2026-04-23 | 9.6 Critical |
| MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheAuthenticate.apacheEnv is configured to use a user-controlled server variable instead of REMOTE_USER (such as in certain proxy setups). An attacker able to control that value can manipulate the LDAP search filter and potentially bypass authentication constraints or cause unauthorized LDAP queries. This vulnerability is fixed in 2.5.36. | ||||
| CVE-2024-54675 | 1 Misp | 1 Misp | 2026-04-15 | 6.1 Medium |
| app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ad-hoc workflow. | ||||
| CVE-2024-54674 | 1 Misp | 1 Misp | 2026-04-15 | 6.1 Medium |
| app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom clusters into the misp-galaxy format. | ||||
| CVE-2025-66386 | 1 Misp | 1 Misp | 2026-04-15 | 4.1 Medium |
| app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin. | ||||
| CVE-2025-66384 | 1 Misp | 1 Misp | 2026-04-15 | 8.2 High |
| app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name. | ||||
| CVE-2025-67906 | 2 Misp, Misp-project | 2 Misp, Misp | 2025-12-21 | 5.4 Medium |
| In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path. | ||||
| CVE-2024-29858 | 2 Misp, Misp-project | 2 Misp, Misp | 2025-06-17 | 9.8 Critical |
| In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload. | ||||
| CVE-2024-46918 | 2 Misp, Misp-project | 2 Misp, Misp | 2025-03-13 | 9.8 Critical |
| app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org. | ||||
| CVE-2024-29859 | 2 Misp, Misp-project | 2 Misp, Misp | 2024-11-21 | 9.8 Critical |
| In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload. | ||||
| CVE-2020-12889 | 1 Misp | 1 Misp-maltego | 2024-11-21 | 9.8 Critical |
| MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case. | ||||
| CVE-2024-45509 | 2 Misp, Misp-project | 2 Misp, Misp | 2024-09-04 | 9.8 Critical |
| In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin. | ||||