Vulnerabilities > Misp > Low

DATE CVE VULNERABILITY TITLE RISK
2022-03-18 CVE-2022-27244 Cross-site Scripting vulnerability in Misp
An issue was discovered in MISP before 2.4.156.
network
misp CWE-79
3.5
2021-07-30 CVE-2021-37743 Cross-site Scripting vulnerability in Misp 2.4.147
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.
network
misp CWE-79
3.5
2021-07-26 CVE-2021-37534 Cross-site Scripting vulnerability in Misp 2.4.146
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
network
misp CWE-79
3.5
2021-03-02 CVE-2021-27904 Unspecified vulnerability in Misp
An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139.
local
low complexity
misp
2.1
2019-03-01 CVE-2019-9482 Information Exposure vulnerability in Misp 2.4.102
In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for.
network
misp CWE-200
3.5