← All credits
iglocska
81 vulnerability records and advisories credit this contributor.
CVE-2026-106513
MISP: Site-Admin Can Repoint Redis Workers to Attacker-Controlled Server via UI/API Configuration Change
CVE-2026-106512
MISP sachertortephp - CakeResponse::download() HTTP Response Splitting via Unsanitized Filename Enables Stored XSS
CVE-2026-104914
MISP: Soft-Deleted Attributes from Other Organizations Exposed via Attribute Search and Paginated View
CVE-2026-104912
MISP Correlation Authorization Bypass Exposes Restricted Event and Attribute Data
CVE-2026-104910
MISP Information Disclosure via Related Events Listing Bypassing Per-Event Authorization
CVE-2026-104908
MISP Decaying Model Import Mass Assignment Allows Cross-Organization Model Overwrite and Default Flagging
CVE-2026-104907
MISP: JavaScript Injection via Remote Tag ID in Event Preview Inline Handler
CVE-2026-104906
MISP TAXII Object Viewer Stored XSS via Unescaped JSON Output
CVE-2026-104901
MISP ID Translator: Unescaped Remote Event ID Enables Cross-Site Scripting via Linked Server
CVE-2026-104900
MISP Stored XSS via Unescaped Count Field Value in Remote Event Preview Index