CVE-2026-9136
- EPSS 0.23%
- Veröffentlicht 20.05.2026 18:39:40
- Zuletzt bearbeitet 23.07.2026 15:10:00
A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the record. Because the underlying framework treats a s...
- EPSS 0.18%
- Veröffentlicht 20.05.2026 14:22:59
- Zuletzt bearbeitet 23.07.2026 12:10:00
MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based on the email claim when the local account had no stored sub value. Under insecure or untrusted IdP configurations where email owne...
CVE-2026-44379
- EPSS 0.18%
- Veröffentlicht 13.05.2026 20:53:36
- Zuletzt bearbeitet 22.06.2026 19:23:18
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid field. As a result, a user able to create or modify Collection records could submit malformed UUID...
CVE-2026-44380
- EPSS 0.4%
- Veröffentlicht 13.05.2026 20:51:30
- Zuletzt bearbeitet 22.06.2026 19:23:18
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organization administrator to reset authentication keys ...
CVE-2026-44381
- EPSS 0.67%
- Veröffentlicht 13.05.2026 20:50:04
- Zuletzt bearbeitet 22.06.2026 19:23:18
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow attribute listing endpoints. The affected code acce...
CVE-2026-8080
- EPSS 0.14%
- Veröffentlicht 07.05.2026 12:16:18
- Zuletzt bearbeitet 22.06.2026 19:23:18
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows Stored XSS. This issue affects MISP before 2.5.37. A stored cross-site scripting vulnerability exists in the template e...
CVE-2026-39962
- EPSS 0.35%
- Veröffentlicht 09.04.2026 17:16:30
- Zuletzt bearbeitet 22.06.2026 19:23:18
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username value when ApacheAuthenticate.a...
- EPSS 0.32%
- Veröffentlicht 15.12.2025 03:25:46
- Zuletzt bearbeitet 22.06.2026 19:23:18
In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.
CVE-2025-66384
- EPSS 0.35%
- Veröffentlicht 28.11.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.
CVE-2025-66386
- EPSS 0.3%
- Veröffentlicht 28.11.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.