CVE-2020-8891Medium· 5.9▾ SunlitAn issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.4%
1.4% → 1.4%
An issue was discovered in MISP before 2.4.121. It did not canonicalize usernames when trying to block a brute-force series of invalid requests.
misp < 2.4.121Upgrade past the affected range:
misp 2.4.121Connected by shared product, vendor, weakness, or advisory.
CVE-2020-8892High· 8.1An issue was discovered in MISP before 2.4.121
CVE-2020-8890Medium· 5.9An issue was discovered in MISP before 2.4.121
CVE-2020-8894Medium· 6.5An issue was discovered in MISP before 2.4.121
CVE-2020-8893High· 7.5An issue was discovered in MISP before 2.4.121
CVE-2026-94277Medium· 6.3MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding
CVE-2026-85237High· 8.1A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when va…