📦 Misp

by Misp

🔍 What is Misp?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-29858

CRITICAL CVSS 9.8 Mar 21, 2024

This vulnerability in MISP (Malware Information Sharing Platform) allows attackers to upload malicious files through the logo upload functionality. It affects all MISP instances running versions befor...

CVE-2024-25674

CRITICAL CVSS 9.8 Feb 9, 2024

This vulnerability in MISP allows attackers to upload malicious files disguised as organization logos due to insufficient file extension and MIME type validation. Attackers could execute arbitrary cod...

CVE-2023-50918

CRITICAL CVSS 9.8 Dec 15, 2023

CVE-2023-50918 is an access control vulnerability in MISP's audit logs controller that allows unauthorized users to view audit logs. This affects all MISP instances running versions before 2.4.182. Th...

CVE-2022-48328

CRITICAL CVSS 9.8 Feb 20, 2023

This vulnerability in MISP (Malware Information Sharing Platform) allows SQL injection through mishandled URL parameters in the IndexFilterComponent. Attackers can exploit this to execute arbitrary SQ...

CVE-2022-29528

CRITICAL CVSS 9.8 Apr 20, 2022

CVE-2022-29528 is a PHAR deserialization vulnerability in MISP (Malware Information Sharing Platform) that allows attackers to execute arbitrary code on affected systems. This affects all MISP instanc...

CVE-2021-39302

CRITICAL CVSS 9.8 Aug 19, 2021

This vulnerability allows SQL injection in MISP (Malware Information Sharing Platform) through the Log.php component. Attackers can execute arbitrary SQL commands by manipulating the 'org' parameter v...

CVE-2021-35502

CRITICAL CVSS 9.8 Jun 25, 2021

CVE-2021-35502 is a critical vulnerability in MISP (Malware Information Sharing Platform) that allows cross-site scripting (XSS) attacks due to improper input sanitization in generic field templates. ...

CVE-2021-25323

CRITICAL CVSS 9.1 Jan 19, 2021

CVE-2021-25323 is an authentication bypass vulnerability in MISP (Malware Information Sharing Platform) where users could change their passwords without providing their current password. This affects ...

CVE-2024-58130

HIGH CVSS 7.2 Mar 28, 2025

This vulnerability in MISP (Malware Information Sharing Platform) allows cross-site scripting (XSS) attacks through REST endpoints that return non-JSON responses without proper sanitization. Attackers...

CVE-2022-29534

HIGH CVSS 7.5 Apr 20, 2022

This vulnerability allows attackers to bypass password confirmation requirements in MISP by sending requests with an 'Accept: application/json' header. This affects all MISP instances running versions...

CVE-2022-27243

HIGH CVSS 7.8 Mar 18, 2022

This vulnerability in MISP allows attackers to perform Local File Inclusion (LFI) through the custom terms file setting. It enables reading arbitrary files on the server, potentially exposing sensitiv...

CVE-2022-27245

HIGH CVSS 8.8 Mar 18, 2022

CVE-2022-27245 is a Server-Side Request Forgery (SSRF) vulnerability in MISP (Malware Information Sharing Platform) that allows attackers to make unauthorized requests from the vulnerable server to in...

CVE-2021-31780

HIGH CVSS 7.5 Apr 23, 2021

This vulnerability in MISP allows information disclosure when editing events with sharing groups. An incorrect sharing group association causes the system to reuse a local ID instead of the proper sha...

CVE-2025-67906

MEDIUM CVSS 5.4 Dec 15, 2025

This vulnerability allows cross-site scripting (XSS) attacks in MISP's workflow execution path. Attackers can inject malicious scripts that execute in users' browsers when viewing workflow execution d...

CVE-2024-58128

MEDIUM CVSS 5.5 Mar 28, 2025

This vulnerability allows attackers with admin privileges in MISP to inject malicious scripts via menu_custom_right_link parameters through the web interface, leading to cross-site scripting (XSS) att...