Vulnerabilities
Summary — last 7 days
New vulnerabilities3,333▲ 343 vs. last week
Critical / high1,493▲ 121 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 117 vs. last week
240 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.6) | — | — | MispAI | 10/1/2026 | 10/1/2026 | MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic compared the submitted token against a counter value that was cached in the user's session at the time the password was… | |
| Deferred | Medium (6.2) | — | — | MispAI | 9/30/2026 | 9/30/2026 | MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy add, edit, and sync/import capture endpoints. The stored value was subsequently concatenated directly into HTML markup… | |
| Deferred | Medium (6.2) | — | — | MispAI | 9/30/2026 | 9/30/2026 | MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: URI scheme, a user with galaxy editor privileges on the local instance or on a synced instance could store a javascript:… | |
| Deferred | High (8.3) | — | — | MispAI | 9/30/2026 | 9/30/2026 | MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was accepted and stored without server-side validation. On the client side, the stored value was rendered into an HTML img element's src attribute via string concatenation, allowing a… | |
| Deferred | High (8.6) | — | — | MispAI | 9/30/2026 | 9/30/2026 | MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-association save operation, which writes not only the intended tag collection record but also any associated model data… | |
| Deferred | High (8.3) | 0.39% | — | MispAI | 9/30/2026 | 9/30/2026 | MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture, shadow attribute proposal, event report creation, object reference add, user admin edit), the application sanitizes the… | |
| Deferred | High (8.7) | 0.36% | — | MispAI | 9/30/2026 | 9/30/2026 | MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the event identified in the URL but then persisted the entire submitted record, including caller-supplied fields such as the… | |
| Deferred | Medium (6.3) | 0.32% | — | Misp ModulesAI | 9/25/2026 | 9/25/2026 | The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values (IP address, login, password, domain ID, policy ID) and MISP attribute values (destination IPs, URLs, event… | |
| Deferred | High (7.7) | 0.39% | — | MispAICakephpAI | 9/22/2026 | 9/22/2026 | MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences: No component of MISP, the vendored CakePHP framework, or any runtime-loaded library reads or… | |
| Deferred | Medium (5.3) | 0.41% | — | MispAI | 9/22/2026 | 9/22/2026 | A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a trailing asterisk) instead of the correct 'theming_enabled'. In the MISP ACL system, the array values define which role or permission… | |
| Deferred | Medium (6.9) | 0.54% | — | Misp-project MispAI | 9/22/2026 | 9/22/2026 | In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The query selected only User.password, User.totp, and User.hotp_counter. When the TOTP branch… | |
| Deferred | Medium (5.1) | 0.51% | — | MispAI | 9/22/2026 | 9/22/2026 | In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the value corresponded to a genuine PHP file upload via is_uploaded_file. An authenticated site-admin user could supply an… | |
| Deferred | Medium (5.1) | 0.76% | — | MispAI | 9/22/2026 | 9/22/2026 | In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence of an organization logo image. The original code called file_exists() with a path constructed as APP . 'webroot' . DS . 'img' . DS . 'orgs' . DS . $k . '.png',… | |
| Deferred | Medium (5.3) | 0.72% | — | MispAI | 9/22/2026 | 9/22/2026 | The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organization identifier with a fixed image directory and a file extension, then calls file_exists() on the resulting path. The organization name field is attacker-controllable through event import, which sets… | |
| Deferred | Medium (5.3) | 0.38% | — | MispAI | 9/22/2026 | 9/22/2026 | MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata fields without verifying that the invoking user holds sufficient privileges. A user with a sharing group (SG) editor role can trigger… | |
| Deferred | Medium (5.3) | 0.51% | — | MispAI | 9/22/2026 | 9/22/2026 | In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP upload via is_uploaded_file(). An authenticated user holding the perm_add permission… | |
| Deferred | Medium (5.3) | 0.35% | — | MispAI | 9/22/2026 | 9/22/2026 | MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of suggestion content within an event report, was incorrectly mapped to the wildcard permission ('*') in the ACLComponent, making it accessible to any authenticated user regardless of… | |
| Deferred | Medium (5.3) | 0.39% | — | MispAI | 9/22/2026 | 9/22/2026 | In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrichment logic fetched the report using only the event ID as the lookup condition, without applying the report's own distribution/ACL constraints. Because MISP reports carry an independent distribution… | |
| Deferred | Medium (4.8) | 0.42% | — | MispAI | 9/22/2026 | 9/22/2026 | MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MISP.org organization name setting was interpolated directly into a JavaScript string literal using an unescaped PHP echo: var org = "<?php echo $org;?>";. Because the value was placed inside a double-quoted… | |
| Deferred | Medium (6.9) | 0.60% | — | MispAI | 9/22/2026 | 9/22/2026 | MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build() library contains a logic error in its readFile guard condition (readFile && http || https), where PHP operator precedence causes the https branch to bypass the readFile check entirely. As a… | |
| Deferred | Medium (5.3) | 0.41% | — | MispAI | 9/22/2026 | 9/22/2026 | In MISP, the queryEnrichment method in EventsController.php accepted a module name parameter and iterated over the list of enabled modules to find a match. If the specified module was not present in the enabled modules list, the code silently continued processing using default parameters (format set to 'simplified'… | |
| Deferred | Medium (5.3) | 0.37% | — | MispAI | 9/22/2026 | 9/22/2026 | In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and element capture only when the HTTP request method was POST. However, the underlying CRUDComponent::add() method persists data on both POST and PUT requests. As a result, an authenticated user could issue a PUT… | |
| Deferred | Medium (6.9) | 0.18% | — | MispAI | 9/22/2026 | 9/22/2026 | The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_install.log and a named pipe (FIFO) at /var/log/misp_install.log.pipe to capture all installer output. The log captures highly sensitive data including the generated admin password, database passwords,… | |
| Deferred | Medium (5.1) | 0.54% | — | MispAI | 9/22/2026 | 9/22/2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. The view template app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp renders a URL-supplied event ID list into a single-quoted JavaScript string literal using PHP's json_encode() without… | |
| Deferred | Medium (5.1) | 0.44% | — | Misp-project MispAI | 9/22/2026 | 9/22/2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal inside an onClick HTML attribute without any encoding or escaping. An attacker who can… |