VulnSea

misp-project has 113 CVEs on record between 2016 and 2026. Disclosure cadence is accelerating: 20 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 20. The median CVSS is 6.1 (medium), with 25 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (45) and CWE-862 (12).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
—
Last 90 days
20 prev 0

Products

  • misp 113
113
Total CVEs
25
Critical
0
CISA KEV
0
Exploited

misp-project vulnerabilities

CVEs affecting misp-project, newest first. Open any entry for full detail, references, and exploit status.

113 CVEsRSS

CVE-2024-25674Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.184

An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.

▾ Midnightmisp-project · mispEPSS 0.78%via NVD
CVE-2023-50918Critical· 9.8
2y ago

app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.

app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.

▾ Midnightmisp-project · mispEPSS 0.79%via NVD
CVE-2023-49926Medium· 6.1
2y ago

app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.

app/Lib/Tools/EventTimelineTool.php in MISP before 2.4.179 allows XSS in the event timeline widget.

▾ Sunlitmisp-project · mispEPSS 0.41%via NVD
CVE-2023-48659Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.

▾ Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-48658Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.

▾ Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-48657Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.

▾ Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-48656Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.

▾ Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-48655Critical· 9.8
2y ago

An issue was discovered in MISP before 2.4.176

An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.

▾ Midnightmisp-project · mispEPSS 0.92%via NVD
CVE-2023-41098Medium· 6.1
3y ago

An issue was discovered in MISP 2.4.174

An issue was discovered in MISP 2.4.174. In app/Controller/DashboardsController.php, a reflected XSS issue exists via the id parameter upon a dashboard edit.

▾ Sunlitmisp-project · mispEPSS 0.42%via NVD
CVE-2023-40224Medium· 6.1
3y ago

MISP 2.4.174 allows XSS in app/View/Events/index.ctp.

MISP 2.4.174 allows XSS in app/View/Events/index.ctp.

▾ Sunlitmisp-project · mispEPSS 0.43%via NVD
CVE-2023-37307Medium· 5.4
3y ago

In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.

In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.

▾ Sunlitmisp-project · mispEPSS 0.50%via NVD
CVE-2023-37306High· 7.5
3y ago

MISP 2.4.172 mishandles different certificate file extensions in server sync

MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

▾ Twilightmisp-project · mispEPSS 0.53%via NVD
CVE-2023-28884Medium· 6.1
3y ago

In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.

In MISP 2.4.169, app/Lib/Tools/CustomPaginationTool.php allows XSS in the community index.

▾ Sunlitmisp-project · mispEPSS 0.41%via NVD
CVE-2023-28607Medium· 6.1
3y ago

js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.

js/event-graph.js in MISP before 2.4.169 allows XSS via the event-graph relationship tooltip.

▾ Sunlitmisp-project · mispEPSS 0.38%via NVD
CVE-2023-28606Medium· 6.1
3y ago

js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.

js/event-graph.js in MISP before 2.4.169 allows XSS via event-graph node tooltips.

▾ Sunlitmisp-project · mispEPSS 0.38%via NVD
CVE-2022-48329Critical· 9.8
3y ago

MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.

MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.

▾ Midnightmisp-project · mispEPSS 0.94%via NVD
CVE-2022-48328Critical· 9.8
3y ago

app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

▾ Midnightmisp-project · mispEPSS 1.3%via NVD
CVE-2023-24070Medium· 6.1
3y ago

app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.

app/View/AuthKeys/authkey_display.ctp in MISP through 2.4.167 has an XSS in authkey add via a Referer field.

▾ Sunlitmisp-project · mispEPSS 0.41%via NVD
CVE-2023-24027Medium· 6.1
3y ago

In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.

In MISP 2.4.167, app/webroot/js/action_table.js allows XSS via a network history name.

▾ Sunlitmisp-project · mispEPSS 0.40%via NVD
CVE-2022-47928Medium· 6.1
3y ago

In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.

In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.

▾ Sunlitmisp-project · mispEPSS 0.41%via NVD
CVE-2022-42724Medium· 4.3
3y ago

app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).

app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).

▾ Sunlitmisp-project · mispEPSS 0.49%via NVD
CVE-2022-29534High· 7.5
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.

▾ Twilightmisp-project · mispEPSS 1.6%via NVD
CVE-2022-29533Medium· 6.1
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page."

▾ Sunlitmisp-project · mispEPSS 0.84%via NVD
CVE-2022-29532Medium· 4.8
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.

▾ Sunlitmisp-project · mispEPSS 0.84%via NVD
CVE-2022-29531Medium· 5.4
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.

▾ Sunlitmisp-project · mispEPSS 0.83%via NVD
CVE-2022-29530Medium· 5.4
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.

▾ Sunlitmisp-project · mispEPSS 0.83%via NVD
CVE-2022-29529Medium· 5.4
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.

▾ Sunlitmisp-project · mispEPSS 0.83%via NVD
CVE-2022-29528Critical· 9.8
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.

▾ Midnightmisp-project · mispEPSS 2.2%via NVD
CVE-2022-27246Medium· 6.1
4y ago

An issue was discovered in MISP before 2.4.156

An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default.

▾ Sunlitmisp-project · mispEPSS 0.60%via NVD
CVE-2022-27245High· 8.8
4y ago

An issue was discovered in MISP before 2.4.156

An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.

▾ Twilightmisp-project · mispEPSS 0.90%via NVD
misp-project vulnerabilities (CVEs) — page 2 · VulnSea