misp-project
30 known vulnerabilities affecting misp-project products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-85216 | Medium | 0.5% | 9.8 | MISP contains an authentication bypass vulnerability in its LDAP and LinOTP auth… | |
| CVE-2026-9137 | Medium | 0.4% | 7.5 | The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but… | |
| CVE-2026-10611 | Medium | 0.4% | 10.0 | An authentication bypass vulnerability exists in MISP when LDAP mixed authentica… | |
| CVE-2026-86452 | Medium | 0.3% | 7.5 | Affected versions of MISP permit unauthenticated or weakly constrained request p… | |
| CVE-2026-85237 | Medium | 0.3% | 8.1 | A vulnerability in MISP's email-based one-time password (OTP) authentication flo… | |
| CVE-2026-86419 | Medium | 0.2% | 9.1 | Affected versions of MISP contain insufficient validation of server-side outboun… | |
| CVE-2026-10863 | Medium | 0.2% | 8.1 | A security issue was fixed in the correlations over-correlation endpoint where t… | |
| CVE-2026-85236 | Medium | 0.2% | 8.8 | A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents… | |
| CVE-2026-85221 | Medium | 0.1% | 9.1 | MISP contains an improper TLS certificate validation vulnerability in CurlClient… | |
| CVE-2026-86347 | Low | 0.3% | 6.5 | Affected versions of MISP allow any authenticated user to access TemplatesContro… | |
| CVE-2026-85239 | Low | 0.3% | 6.5 | A vulnerability in MISP's event template handling allowed an authenticated user … | |
| CVE-2026-9136 | Low | 0.2% | 6.5 | A vulnerability was identified in the ShadowAttribute proposal creation workflow… | |
| CVE-2026-10861 | Low | 0.2% | 6.1 | An open redirect vulnerability existed in MISP UsersController::routeafterlogin(… | |
| CVE-2026-85238 | Low | 0.2% | 6.8 | MISP contains a session fixation vulnerability in the CustomAuth authentication … | |
| CVE-2026-86342 | Low | 0.2% | 4.3 | Affected versions of MISP contain improper authorization checks in the freetext … | |
| CVE-2026-86408 | Low | 0.2% | 6.5 | Affected versions of MISP do not enforce parent-event visibility when serving cr… | |
| CVE-2026-10860 | Low | 0.2% | 6.5 | A logic error in the MISP CRUD component delete handler allowed validation failu… | |
| CVE-2026-86351 | Low | 0.2% | 6.1 | Affected versions of MISP validate the user-configurable homepage by checking on… | |
| CVE-2026-10854 | Low | 0.2% | 4.3 | A visibility control issue in the event template creation workflow allowed non-s… | |
| CVE-2026-10864 | Low | 0.2% | 4.3 | A vulnerability in the MISP dashboard widgets allowed an authenticated user to m… | |
| CVE-2026-86451 | Low | 0.2% | 4.3 | Affected versions of MISP allow authenticated users to retrieve object-reference… | |
| CVE-2026-85230 | Low | 0.2% | 5.4 | A persistent unsafe URL injection vulnerability exists in the MISP dashboard But… | |
| CVE-2026-86441 | Low | 0.2% | 4.3 | Affected versions of MISP contain inconsistent authorization checks across dashb… | |
| CVE-2026-86417 | Low | 0.2% | 4.3 | Affected versions of MISP inconsistently enforced email-address visibility in Da… | |
| CVE-2026-86418 | Low | 0.2% | 4.3 | Affected versions of MISP expose organisation metadata through the dashboard org… | |
| CVE-2026-85227 | Low | 0.2% | 6.1 | MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event … | |
| CVE-2026-10855 | Low | 0.2% | 4.3 | An authorization flaw existed in the MISP Event Template Importer overwrite work… | |
| CVE-2026-85226 | Low | 0.2% | 4.3 | MISP contains an authorization flaw in the OnDemand correlation engine where cor… | |
| CVE-2026-10856 | Low | 0.1% | 6.1 | A URL validation flaw in the MISP dashboard button widget allowed a crafted rela… | |
| CVE-2026-86440 | Low | 0.1% | 5.4 | Affected versions of MISP insufficiently validate URLs used by dashboard widgets… |