# MISP Discloses Full CVE History List

Published: 0001-01-01 · Severity: low
Canonical: https://vorant.io/reports/cb05c915-b2d3-5917-a281-f65afc5a6c34/misp-discloses-full-cve-history-list

> MISP project's security page catalogs its vulnerability disclosure policy and lists over 100 historical CVEs affecting the MISP threat-intelligence platform from 2015 through 2026.

This is the official MISP Project security disclosure page, not an incident report. It describes the coordinated disclosure process (reports go to CIRCL, PGP-encrypted, with a ~48 hour fix turnaround) and then enumerates the full historical list of CVEs and GCVEs affecting MISP core and MISP modules since 2015. The overwhelming majority of issues are cross-site scripting (stored and reflected) in various UI views (galaxy clusters, event graphs, sighting popovers, dashboards, templates), alongside a smaller number of more serious findings including PHP object injection, PHAR deserialization, SSRF, local file inclusion, SQL injection, authentication/ACL bypasses, and a few remote command execution issues tied to admin-level functionality.

Notably, none of the CVEs listed are described as under active exploitation; this is a transparency/changelog resource intended to help MISP operators (heavily used by CSIRTs and critical-infrastructure defenders) track patch status across releases from 2.3.x through the current 2.5.x/GCVE-numbered advisories. The page itself carries no indication of in-the-wild abuse, malware, or attacker attribution — it is a vulnerability management reference rather than a threat report.

## Mentioned in this report

- Vulnerabilities: CVE-2015-5719, CVE-2015-5720, CVE-2015-5721, CVE-2017-13671, CVE-2017-14337, CVE-2017-15216, CVE-2017-16802, CVE-2017-16946, CVE-2017-7215, CVE-2018-11245, CVE-2018-11562, CVE-2018-12649, CVE-2018-19908 (poc), CVE-2018-6926, CVE-2018-8948, CVE-2018-8949, CVE-2019-10254, CVE-2019-11812, CVE-2019-11813, CVE-2019-11814, CVE-2019-12794, CVE-2019-12868, CVE-2019-14286, CVE-2019-16202, CVE-2019-19379, CVE-2019-9482, CVE-2020-10246, CVE-2020-10247, CVE-2020-13153, CVE-2020-14969, CVE-2020-15411, CVE-2020-15412, CVE-2020-25766, CVE-2020-28043, CVE-2020-28947, CVE-2020-8890, CVE-2020-8891, CVE-2020-8892, CVE-2020-8893, CVE-2020-8894

Source reporting: https://www.misp-project.org/security

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/cb05c915-b2d3-5917-a281-f65afc5a6c34/misp-discloses-full-cve-history-list.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
