CVE-2023-48657Critical· 9.8▾ MidnightAn issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
0.9% → 0.9%
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
misp < 2.4.176Upgrade past the affected range:
misp 2.4.176Connected by shared product, vendor, weakness, or advisory.
CVE-2023-48658Critical· 9.8An issue was discovered in MISP before 2.4.176
CVE-2023-48659Critical· 9.8An issue was discovered in MISP before 2.4.176
CVE-2023-48656Critical· 9.8An issue was discovered in MISP before 2.4.176
CVE-2023-48655Critical· 9.8An issue was discovered in MISP before 2.4.176
CVE-2026-95806High· 7.7MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences: - any fil…
CVE-2026-95805Medium· 5.3A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a trailing asterisk) instead of the correct 'theming_enabl…