Misp
215 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Misp, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
Misp CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 3 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 2 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 7 |
| 2026-06 | 27 |
| 2026-07 | 4 |
| 2026-08 | 0 |
| 2026-09 | 72 |
Severity
How the 215 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical28
- High28
- Medium88
Latest CVEs
The 15 most recently published vulnerabilities affecting Misp.
- CVE-2026-95806MISP: PHP phar stream wrapper enables deserialization and code execution via caller-influenced filesystem paths—
- CVE-2026-95805MISP ACLComponent: Typo in previewEventAttributes ACL key bypasses intended access restriction—
- CVE-2026-95754MISP: Disabled-user check ineffective in pre-authentication TOTP login branch—
- CVE-2026-95703MISP OrganisationsController File Existence and Image-Type Oracle via Forged Upload tmp_name—
- CVE-2026-95701MISP Path Traversal via Organization Name in Org-Statistics Logo Check—
- CVE-2026-95698MISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization Name—
- CVE-2026-95697MISP: Insufficient Authorization Allows Sharing Group Editors to Overwrite Organization Metadata—
- CVE-2026-95693MISP Information Disclosure via Forged Upload Path—
- CVE-2026-95685MISP Missing Authorization on replaceSuggestionInReport Event Report Action—
- CVE-2026-95683MISP Overmind Event View Discloses Report Content Bypassing Report-Level ACL—
- CVE-2026-95682MISP Stored Cross-Site Scripting via Unescaped Organization Name in Admin Email View—
- CVE-2026-95679MISP Unauthenticated Blind SSRF via XML Body Processing—
- CVE-2026-95674MISP EventsController queryEnrichment allows querying unavailable or legacy modules without validation—
- CVE-2026-95671MISP Collections: Missing Authorization Check for Sharing Group on PUT Request in collections/add—
- CVE-2026-95667MISP Installer Log and FIFO Created World-Readable, Exposing Sensitive Credentials—
Product grouping is registry-driven, with AI assist and human review. How it works