Misp
Vendor:
First CVE: Sep 3, 2016 · Active for 9 years
142
Total CVEs
More Total CVEs than 99% of tracked products
12.9
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Misp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 3, 2016
9 years ago
Most Recent CVE
Jul 9, 2026
16 days ago
CVE Severity & Scoring
Misp142 CVEs
61%
20%
20%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (1.4%)
Network139 (97.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low135 (95.1%)
High7 (4.9%)
Unknown0 (0.0%)
User Interaction
None83 (58.5%)
Unknown0 (0.0%)
Required56 (39.4%)
Privileges Required
Low38 (26.8%)
High17 (12.0%)
None87 (61.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (142 CVEs).
142 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19908HIGH An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulne | Dec 6, 2018 | 8.8 | 46 | NO | YES |
CVE-2026-10611CRITICAL An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Sec | Jun 2, 2026 | 10.0 | 40 | NO | NO |
CVE-2026-56425HIGH The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important secu | Jun 22, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-56422CRITICAL Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_ | Jun 22, 2026 | 9.4 | 36 | NO | NO |
CVE-2026-10868CRITICAL A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit re | Jun 4, 2026 | 9.0 | 35 | NO | NO |
CVE-2026-56423HIGH MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using br | Jun 22, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-44381MEDIUM MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in th | May 13, 2026 | 5.3 | 33 | NO | YES |
CVE-2026-56424HIGH MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on w | Jun 22, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-54361HIGH MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegations, and shadow attributes. Several controller actions accept | Jun 12, 2026 | 8.8 | 32 | NO | NO |
CVE-2025-67906CRITICAL In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path. | Dec 15, 2025 | 9.0 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (142 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.7% of CVEs· 96th percentile
ExploitDB
1 CVE
0.7% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (142 CVEs).
Media Mentions
Signals from CVEs in this product scope (142 CVEs).
Top CNAs Publishing CVEs For Misp
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.4.92 | 1 | 9.8 | 1.5% | 0 | 0 |
| 2.4.91 | 2 | 6.1 | 0.8% | 0 | 0 |
| 2.4.87 | 1 | 7.2 | 1.6% | 0 | 0 |
| 2.4.82 | 2 | 5.2 | 0.8% | 0 | 0 |
| 2.4.174 | 2 | 6.1 | 0.4% | 0 | 0 |
| 2.4.172 | 1 | 7.5 | 0.5% | 0 | 0 |
| 2.4.169 | 1 | 6.1 | 0.4% | 0 | 0 |
| 2.4.167 | 3 | 7.3 | 0.5% | 0 | 0 |
| 2.4.148 | 1 | 9.8 | 0.9% | 0 | 0 |
| 2.4.147 | 2 | 5.4 | 0.6% | 0 | 0 |
| 2.4.146 | 1 | 5.4 | 0.5% | 0 | 0 |
| 2.4.144 | 1 | 9.8 | 1.1% | 0 | 0 |
| 2.4.141 | 1 | 7.5 | 1.0% | 0 | 0 |
| 2.4.136 | 4 | 6.8 | 0.9% | 0 | 0 |
| 2.4.135 | 1 | 6.1 | 0.8% | 0 | 0 |
| 2.4.134 | 1 | 6.1 | 0.8% | 0 | 0 |
| 2.4.128 | 3 | 6.7 | 1.0% | 0 | 0 |
| 2.4.127 | 1 | 7.5 | 1.3% | 0 | 0 |
| 2.4.122 | 2 | 6.1 | 0.8% | 0 | 0 |
| 2.4.118 | 1 | 5.3 | 1.1% | 0 | 0 |