CVE-2026-103662Medium· 5.1▾ SunlitMISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag). The affected forms echoed a user-supplied tag name value from the request unescaped i…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 28.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag).
The affected forms echoed a user-supplied tag name value from the request unescaped into the rendered HTML output. An attacker who can induce a site administrator to visit a crafted URL containing a malicious tag name parameter can execute arbitrary JavaScript in the administrator's browser session.
Preconditions:
The target must be running a MISP instance with the legacy taxonomy tag confirmation views enabled.
The victim must be an authenticated site administrator.
The victim must navigate to the attacker-crafted URL (e.g., via a phishing link).
Security impact:
Execution of arbitrary client-side script in the context of the administrator's browser.
Potential theft of session tokens, CSRF tokens, or other sensitive data accessible from the page.
Potential for performing privileged actions on behalf of the administrator within the MISP interface.
Affected versions: <2.5.48.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-28607Medium· 6.1js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
CVE-2023-28606Medium· 6.1js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
CVE-2023-24027Medium· 6.1In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
CVE-2026-103664Medium· 4.8MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel
CVE-2026-103389Medium· 6.2MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path
CVE-2026-103388Medium· 6.2MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL validation