The MISP Project maintains a threat-intelligence sharing platform widely used by security teams, government agencies, and incident-response organizations to collaborate on malware samples, indicators, and threat campaigns. The vendor's vulnerability footprint, while modestly represented in the landscape, concentrates on a single core product and recurs through cross-site scripting weaknesses characteristic of web-facing applications that handle user-supplied threat data and metadata. This exposure pattern reflects the platform's role as a central repository and collaboration hub where input validation at multiple points—user submissions, API endpoints, and data imports—becomes critical to preventing script injection and data-integrity compromise. Defenders deploying MISP instances should prioritize input sanitization controls and maintain current patching of the platform tier itself. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Misp Project over time
Signals from CVEs in this vendor scope (143 CVEs).
143 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19908HIGH An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulne | Dec 6, 2018 | 8.8 | 46 | NO | YES |
CVE-2026-10611CRITICAL An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Sec | Jun 2, 2026 | 10.0 | 40 | NO | NO |
CVE-2026-56423HIGH MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using br | Jun 22, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-56425HIGH The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important secu | Jun 22, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-56422CRITICAL Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_ | Jun 22, 2026 | 9.4 | 36 | NO | NO |
CVE-2026-56424HIGH MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on w | Jun 22, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-10868CRITICAL A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit re | Jun 4, 2026 | 9.0 | 35 | NO | NO |
CVE-2026-44381MEDIUM MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in th | May 13, 2026 | 5.3 | 33 | NO | YES |
CVE-2026-56447HIGH MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passe | Jun 22, 2026 | 7.2 | 32 | NO | NO |
CVE-2026-56446HIGH MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled conten | Jun 22, 2026 | 7.2 | 32 | NO | NO |
Signals from CVEs in this vendor scope (143 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Misp Project.
Media articles that mention a CVE ID that affects a product developed by Misp Project — matched by CVE ID, not by vendor name.