CVE-2026-39962
- EPSS 0.14%
- Veröffentlicht 09.04.2026 17:16:30
- Zuletzt bearbeitet 13.04.2026 15:02:27
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheAuthenticate.a...
- EPSS 0.05%
- Veröffentlicht 15.12.2025 03:25:46
- Zuletzt bearbeitet 21.12.2025 01:15:51
In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.
CVE-2025-66386
- EPSS 0.06%
- Veröffentlicht 28.11.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.
CVE-2025-66384
- EPSS 0.07%
- Veröffentlicht 28.11.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.
CVE-2024-58130
- EPSS 0.17%
- Veröffentlicht 28.03.2025 22:15:17
- Zuletzt bearbeitet 15.07.2025 18:49:50
In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses.
CVE-2024-58129
- EPSS 0.22%
- Veröffentlicht 28.03.2025 22:15:17
- Zuletzt bearbeitet 08.07.2025 17:30:50
In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.
CVE-2024-58128
- EPSS 0.22%
- Veröffentlicht 28.03.2025 22:15:17
- Zuletzt bearbeitet 08.07.2025 17:31:44
In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.
CVE-2024-57969
- EPSS 0.12%
- Veröffentlicht 14.02.2025 07:15:32
- Zuletzt bearbeitet 09.07.2025 15:00:03
app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.
CVE-2024-54674
- EPSS 0.13%
- Veröffentlicht 04.12.2024 21:15:25
- Zuletzt bearbeitet 15.04.2026 00:35:42
app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom clusters into the misp-galaxy format.
CVE-2024-54675
- EPSS 0.13%
- Veröffentlicht 04.12.2024 21:15:25
- Zuletzt bearbeitet 15.04.2026 00:35:42
app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ad-hoc workflow.