Vulnerabilities in MISP
145 resultsVexday analysis
O MISP apresenta 13 vulnerabilidades catalogadas, sendo 5 divulgadas nos últimos 90 dias, o que indica atividade contínua de descoberta de falhas. Embora nenhuma esteja sob ataque ativo no momento, 2 vulnerabilidades críticas e a predominância de injeção de conteúdo (CWE-79) requerem atenção, especialmente considerando o papel estratégico da plataforma em ecossistemas de compartilhamento de inteligência de ameaças.
CVE-2026-85236HIGHMISP cullEmptyEvents CSRF Allows Irreversible Deletion of Events via GET RequestEPSS 0.3%CVE-2026-73162MEDIUMcti-transmute CSRF Allows Unauthorized Follow and Notification State ChangesEPSS 0.2%CVE-2026-10868CRITICALMISP user edit endpoint mass assignment vulnerability allows unauthorized user account modificationEPSS 0.2%CVE-2026-86440MEDIUMMISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Backslash URLsEPSS 0.2%CVE-2026-8080MEDIUMMISP core - Stored XSS in MISP template (old engine) element attribute typeEPSS 0.2%CVE-2024-58130HIGHIn app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization for non-JSON responEPSS 0.2%CVE-2026-10863MEDIUMMISP User-controlled order parameter in correlations over-correlation endpointEPSS 0.2%CVE-2026-10861MEDIUMMISP post-login open redirect via pre_login_requested_urlEPSS 0.2%CVE-2026-9084MEDIUMMISP OIDC authentication bypass via automatic email-based account linking under insecure IdP configurationsEPSS 0.2%CVE-2024-58129MEDIUMIn MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with aEPSS 0.2%CVE-2024-58128MEDIUMIn MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin EPSS 0.2%CVE-2026-91857MEDIUMMISP: State-changing actions accessible via GET request enabling CSRFEPSS 0.2%CVE-2026-94404HIGHMISP CSRF vulnerability allows unauthorized attribute modificationEPSS 0.2%CVE-2026-44364CRITICALmisp-modules website - Missing CSRF protection in the website home blueprintEPSS 0.2%CVE-2026-85546HIGHMISP Sharing Group Quick-Edit Actions Allow CSRF via State-Changing GET RequestsEPSS 0.2%CVE-2026-91819MEDIUMMISP: HTTP Method Override Bypasses CSRF and Form Validation in BetterSecurityComponentEPSS 0.2%CVE-2026-10860HIGHMISP CRUDComponent delete validation bypass via operator precedence errorEPSS 0.2%CVE-2026-95667MEDIUMMISP Installer Log and FIFO Created World-Readable, Exposing Sensitive CredentialsEPSS 0.2%CVE-2026-10854MEDIUMUnauthorized exposure of private galaxies in MISP event template creationEPSS 0.2%CVE-2026-10864MEDIUMMISP Dashboard widget field selection may expose restricted user and organisation dataEPSS 0.2%