Vendor
MISP Project vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 25 vulnerabilities in MISP Project: 20 in the last 7 days and 21 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-95806, was published on 22 September 2026. 1 technology has a page of its own.
- Last 7 days
- 20
- Last 90 days
- 21
- Critical, all time
- 1
- Exploited in the wild
- 0
About MISP Project
An open-source project developing a threat intelligence platform for sharing, storing, and correlating indicators of compromise.
MISP Project technologies
Latest MISP Project vulnerabilities
- CVE-2026-95806: MISP remote code execution via unregistered phar stream wrapperinfoEPSS 0.4%
- CVE-2026-95754: MISP UsersController auth bypass via missing disabled-user check in TOTP branchinfoEPSS 0.5%
- CVE-2026-95701: MISP path traversal in organization logo checkinfoEPSS 0.8%
- CVE-2026-95693: MISP EventReport path traversal information disclosureinfoEPSS 0.5%
- CVE-2026-95685: MISP access control flaw in EventReports replaceSuggestionInReportinfoEPSS 0.4%
- CVE-2026-95683: MISP Overmind event view unauthorized report disclosure via insufficient ACL checksinfoEPSS 0.4%
- CVE-2026-95679: MISP RequestHandlerComponent SSRF in cspReport endpointinfoEPSS 0.6%
- CVE-2026-95674: MISP missing module availability validation in queryEnrichmentinfoEPSS 0.4%
- CVE-2026-95671: MISP CollectionsController authorization bypass on PUT requestsinfoEPSS 0.4%
- CVE-2026-95667: MISP installer log world-readable credential exposureinfoEPSS 0.2%
- CVE-2026-95665: MISP reflected XSS in event REST search export confirmation forminfoEPSS 0.5%
- CVE-2026-95661: MISP reflected XSS in attribute histogram viewinfoEPSS 0.4%
- CVE-2026-94404: MISP cross-site request forgery in attribute editinginfoEPSS 0.2%
- CVE-2026-94401: MISP file upload SSRF and arbitrary file readinfoEPSS 0.4%
- CVE-2026-94394: MISP authorization bypass in event attribute and object accessinfoEPSS 0.4%
- CVE-2026-94383: MISP blocklist workflow module arbitrary script executioninfoEPSS 0.5%
- CVE-2026-94381: MISP privilege escalation via read-only API keyinfoEPSS 0.4%
- CVE-2026-94374: MISP insecure direct object reference in processModuleResultsDatainfoEPSS 0.4%
- CVE-2026-94372: MISP stored cross-site scripting in Galaxies index pageinfoEPSS 0.4%
- CVE-2026-94277: MISP galaxy matrix statistics view stored XSS via galaxy nameinfoEPSS 0.4%
- CVE-2026-62143: MISP misp-modules SSRF bypass in html_to_markdown moduleinfoCVSS 8.3
- CVE-2026-53693: MISP BSimVis stored XSS in tag rendering codeinfoCVSS 6.9
- CVE-2026-9806: MISP CTI Transmute stored XSS in notification panelinfoCVSS 6.3
- CVE-2026-44364: MISP misp-modules CSRF in website home blueprintcriticalCVSS 4EPSS 0.2%
- CVE-2026-44363: MISP misp-modules SSRF and improper TLS validation in expansion modulesmediumCVSS 4EPSS 0.1%
Most severe MISP Project vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-44364: MISP misp-modules CSRF in website home blueprintcriticalCVSS 4EPSS 0.2%
- CVE-2026-44363: MISP misp-modules SSRF and improper TLS validation in expansion modulesmediumCVSS 4EPSS 0.1%
- CVE-2026-62143: MISP misp-modules SSRF bypass in html_to_markdown moduleinfoCVSS 8.3
- CVE-2026-53693: MISP BSimVis stored XSS in tag rendering codeinfoCVSS 6.9
- CVE-2026-9806: MISP CTI Transmute stored XSS in notification panelinfoCVSS 6.3
- CVE-2026-95701: MISP path traversal in organization logo checkinfoEPSS 0.8%
- CVE-2026-95679: MISP RequestHandlerComponent SSRF in cspReport endpointinfoEPSS 0.6%
- CVE-2026-95754: MISP UsersController auth bypass via missing disabled-user check in TOTP branchinfoEPSS 0.5%
- CVE-2026-95665: MISP reflected XSS in event REST search export confirmation forminfoEPSS 0.5%
- CVE-2026-95693: MISP EventReport path traversal information disclosureinfoEPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 20 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/misp-project.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "MISP Project vulnerabilities", https://junglewise.ai/threats/vendors/misp-project, 26 September 2026.