Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Misp-Project

20 known vulnerabilities

2
CRITICAL
8
HIGH
10
MEDIUM

Top Products

misp 20
20 CVEs
7.2
CVE-2026-56447

MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path

7.2
CVE-2026-56446

MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool

8.8
CVE-2026-56425

The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorizat

8.8
CVE-2026-56424

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent

8.8
CVE-2026-56423

MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The af

4.3
CVE-2026-10864

A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influenc

8.1
CVE-2026-10863

A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted fr

6.5
CVE-2026-10860

A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used th

6.1
CVE-2026-10861

An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_lo

6.1
CVE-2026-10856

A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a loc

4.3
CVE-2026-10855

An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template i

4.3
CVE-2026-10854

A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxi

10.0
CVE-2026-10611

An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In

7.5
CVE-2026-9137

The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB

6.5
CVE-2026-9136

A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlle

5.3
CVE-2026-44381

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed

7.2
CVE-2026-44380

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerabili

5.3
CVE-2026-44379

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4

5.4
CVE-2026-8080

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows

9.6
CVE-2026-39962

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special ele

Frequently Asked Questions

How many CVEs affect Misp-Project?

Misp-Project has 20 CVE records in our database, including 2 critical and 8 high severity vulnerabilities.

What are the most severe Misp-Project vulnerabilities?

Misp-Project has 2 critical severity (CVSS 9.0+) and 8 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Misp-Project vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Misp-Project products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Misp-Project Vulnerabilities

CyberStrike scans your infrastructure for Misp-Project vulnerabilities and provides real-time remediation guidance.

Get Started