CVE-2015-5721: Misp-Project Misp

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.

Affected products

Published 2016-09-03. Last modified 2026-06-23.