CVE-2026-104906Medium· 6.2▾ SunlitMISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An atta…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim's MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim's MISP session.
Preconditions:
The victim must be an authenticated MISP user with access to the TAXII object viewer.
The victim must open or view the crafted TAXII object.
Impact:
Execution of arbitrary JavaScript in the victim's browser within the MISP application context.
Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface.
Potential for performing actions on behalf of the authenticated user.
Affected versions: <2.5.48.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-28607Medium· 6.1js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
CVE-2023-28606Medium· 6.1js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
CVE-2023-24027Medium· 6.1In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
CVE-2026-104907Medium· 4.8MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page
CVE-2026-104901Medium· 5.1MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature
CVE-2026-104900Medium· 5.3MISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview