Search
Search Results (74 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-66386 | 1 Misp | 1 Misp | 2026-04-15 | 4.1 Medium |
| app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin. | ||||
| CVE-2024-54675 | 1 Misp | 1 Misp | 2026-04-15 | 6.1 Medium |
| app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ad-hoc workflow. | ||||
| CVE-2024-54674 | 1 Misp | 1 Misp | 2026-04-15 | 6.1 Medium |
| app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom clusters into the misp-galaxy format. | ||||
| CVE-2025-66384 | 1 Misp | 1 Misp | 2026-04-15 | 8.2 High |
| app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name. | ||||
| CVE-2025-67906 | 1 Misp | 1 Misp | 2025-12-21 | 5.4 Medium |
| In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path. | ||||
| CVE-2024-58130 | 1 Misp | 1 Misp | 2025-07-15 | 7.2 High |
| In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responses. | ||||
| CVE-2024-57969 | 1 Misp | 1 Misp | 2025-07-09 | 4.3 Medium |
| app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search. | ||||
| CVE-2024-58128 | 1 Misp | 1 Misp | 2025-07-08 | 5.5 Medium |
| In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link. | ||||
| CVE-2024-58129 | 1 Misp | 1 Misp | 2025-07-08 | 5.5 Medium |
| In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page. | ||||
| CVE-2024-29858 | 2 Misp, Misp-project | 2 Misp, Misp | 2025-06-17 | 9.8 Critical |
| In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload. | ||||
| CVE-2024-46918 | 2 Misp, Misp-project | 2 Misp, Misp | 2025-03-13 | 9.8 Critical |
| app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org. | ||||
| CVE-2024-29859 | 2 Misp, Misp-project | 2 Misp, Misp | 2024-11-21 | 9.8 Critical |
| In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload. | ||||
| CVE-2020-12889 | 1 Misp | 1 Misp-maltego | 2024-11-21 | 9.8 Critical |
| MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case. | ||||
| CVE-2024-45509 | 2 Misp, Misp-project | 2 Misp, Misp | 2024-09-04 | 9.8 Critical |
| In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin. | ||||