MISP Discloses Full CVE History List
MISP project's security page catalogs its vulnerability disclosure policy and lists over 100 historical CVEs affecting the MISP threat-intelligence platform from 2015 through 2026.
This is the official MISP Project security disclosure page, not an incident report. It describes the coordinated disclosure process (reports go to CIRCL, PGP-encrypted, with a ~48 hour fix turnaround) and then enumerates the full historical list of CVEs and GCVEs affecting MISP core and MISP modules since 2015. The overwhelming majority of issues are cross-site scripting (stored and reflected) in various UI views (galaxy clusters, event graphs, sighting popovers, dashboards, templates), alongside a smaller number of more serious findings including PHP object injection, PHAR deserialization, SSRF, local file inclusion, SQL injection, authentication/ACL bypasses, and a few remote command execution issues tied to admin-level functionality.
Notably, none of the CVEs listed are described as under active exploitation; this is a transparency/changelog resource intended to help MISP operators (heavily used by CSIRTs and critical-infrastructure defenders) track patch status across releases from 2.3.x through the current 2.5.x/GCVE-numbered advisories. The page itself carries no indication of in-the-wild abuse, malware, or attacker attribution — it is a vulnerability management reference rather than a threat report.
Mentioned in this report
Source reporting: https://www.misp-project.org/security
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free