vendor

misp-project

11 thingsrelated by NVD

Its products

misp 11

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input…
CVE-2026-86452
Severity high
Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility…
CVE-2026-86418
Severity medium
A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to…
CVE-2026-85239
Severity medium
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully…
CVE-2026-85238
Severity medium
A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of…
CVE-2026-85237
Severity high
A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing…
CVE-2026-85236
Severity high
A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were…
CVE-2026-85230
Severity medium
MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and…
CVE-2026-85227
Severity medium
MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute…
CVE-2026-85226
Severity medium
MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly…
CVE-2026-85221
Severity critical
MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of…
CVE-2026-85216
Severity critical