misp-project has 113 CVEs on record between 2016 and 2026. Disclosure cadence is accelerating: 20 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 20. The median CVSS is 6.1 (medium), with 25 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (45) and CWE-862 (12).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 20 prev 0
Weakness classes
Products
- misp 113
Worst active — by depth score
CVE-2018-19908High· 8.8An issue was discovered in MISP 2.4.9x before 2.4.9964CVE-2026-85216Critical· 9.8MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace Cak…54CVE-2024-29859Critical· 9.8In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.54CVE-2024-29858Critical· 9.8In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.54CVE-2024-25675Critical· 9.8An issue was discovered in MISP before 2.4.18454
misp-project vulnerabilities
CVEs affecting misp-project, newest first. Open any entry for full detail, references, and exploit status.
113 CVEsRSS
CVE-2024-25674Critical· 9.8An issue was discovered in MISP before 2.4.184
An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.
CVE-2023-50918Critical· 9.8app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.
app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.
CVE-2023-49926Medium· 6.1app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.
app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.
CVE-2023-48659Critical· 9.8An issue was discovered in MISP before 2.4.176
An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.
CVE-2023-48658Critical· 9.8An issue was discovered in MISP before 2.4.176
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.
CVE-2023-48657Critical· 9.8An issue was discovered in MISP before 2.4.176
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.
CVE-2023-48656Critical· 9.8An issue was discovered in MISP before 2.4.176
An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.
CVE-2023-48655Critical· 9.8An issue was discovered in MISP before 2.4.176
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
CVE-2023-41098Medium· 6.1An issue was discovered in MISP 2.4.174
An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit.
CVE-2023-40224Medium· 6.1MISP 2.4.174 allows XSS in app/View/Events/index.ctp.
MISP 2.4.174 allows XSS in app/View/Events/index.ctp.
CVE-2023-37307Medium· 5.4In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.
CVE-2023-37306High· 7.5MISP 2.4.172 mishandles different certificate file extensions in server sync
MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.
CVE-2023-28884Medium· 6.1In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.
CVE-2023-28607Medium· 6.1js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.
CVE-2023-28606Medium· 6.1js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.
CVE-2022-48329Critical· 9.8MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
CVE-2022-48328Critical· 9.8app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
CVE-2023-24070Medium· 6.1app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.
CVE-2023-24027Medium· 6.1In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.
CVE-2022-47928Medium· 6.1In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
CVE-2022-42724Medium· 4.3app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).
app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).
CVE-2022-29534High· 7.5An issue was discovered in MISP before 2.4.158
An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.
CVE-2022-29533Medium· 6.1An issue was discovered in MISP before 2.4.158
An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page."
CVE-2022-29532Medium· 4.8An issue was discovered in MISP before 2.4.158
An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.
CVE-2022-29531Medium· 5.4An issue was discovered in MISP before 2.4.158
An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.
CVE-2022-29530Medium· 5.4An issue was discovered in MISP before 2.4.158
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
CVE-2022-29529Medium· 5.4An issue was discovered in MISP before 2.4.158
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
CVE-2022-29528Critical· 9.8An issue was discovered in MISP before 2.4.158
An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
CVE-2022-27246Medium· 6.1An issue was discovered in MISP before 2.4.156
An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default.
CVE-2022-27245High· 8.8An issue was discovered in MISP before 2.4.156
An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.