CVE-2023-48656Critical· 9.8▾ MidnightAn issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
0.9% → 0.9%
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
misp < 2.4.176Upgrade past the affected range:
misp 2.4.176Connected by shared product, vendor, weakness, or advisory.
CVE-2023-48659Critical· 9.8An issue was discovered in MISP before 2.4.176
CVE-2023-48658Critical· 9.8An issue was discovered in MISP before 2.4.176
CVE-2023-48657Critical· 9.8An issue was discovered in MISP before 2.4.176
CVE-2023-48655Critical· 9.8An issue was discovered in MISP before 2.4.176
CVE-2026-94277Medium· 6.3MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding
CVE-2026-85237High· 8.1A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when va…