Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2026-27736
BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks val…
Bigbluebutton
3.0.20+
HIGH 8.2
CVE-2026-27466
BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for…
Bigbluebutton
3.0.22+
HIGH 7.5
CVE-2025-61601
BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user …
Bigbluebutton
3.0.13+
HIGH 7.5
CVE-2025-61602
BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user …
Bigbluebutton
3.0.13+
MEDIUM 5.4
CVE-2025-55200
BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XS…
Bigbluebutton
3.0.13+
MEDIUM 6.1
CVE-2022-36028
Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to …
Greenlight
2.13.0+
MEDIUM 6.1
CVE-2022-36029
Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to …
Greenlight
2.13.0+
MEDIUM 5.4
CVE-2023-43797
BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when…
Bigbluebutton
2.6.11+
MEDIUM 5.4
CVE-2023-43798
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery…
Bigbluebutton
2.6.12+
MEDIUM 5.3
CVE-2023-42804
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an atta…
Bigbluebutton
after 2.5.18
HIGH 8.8
CVE-2023-42803
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the i…
Bigbluebutton
after 2.5.18
MEDIUM 6.5
CVE-2023-33176
BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-S…
Bigbluebutton
2.5.18 / 2.6.9+
HIGH 7.5
CVE-2022-23488
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Da…
Bigbluebutton
2.4+
MEDIUM 5.7
CVE-2022-41964
BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can st…
Bigbluebutton
Patch available
CRITICAL 9.8
CVE-2020-27602
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.
Bigbluebutton
2.2.7+
MEDIUM 6.1
CVE-2022-31065
BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it execut…
Bigbluebutton
2.4.8+
MEDIUM 5.4
CVE-2022-31064
BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack …
Bigbluebutton
2.4.8+
MEDIUM 5.3
CVE-2022-31039
Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though t…
Greenlight
2.12.6+
MEDIUM 5.4
CVE-2022-27238
BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could i…
Bigbluebutton
after 2.4.7
MEDIUM 5.4
CVE-2022-26497
BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the br…
Greenlight
Patch available
MEDIUM 5.3
CVE-2022-29235
BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able t…
Bigbluebutton
2.3.18+
MEDIUM 6.5
CVE-2022-29232
BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circum…
Bigbluebutton
2.3.9+
HIGH 7.5
CVE-2022-29169
BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to re…
Bigbluebutton
2.3.19 / 2.4.7+
MEDIUM 6.1
CVE-2021-4143
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
Bigbluebutton
2.4.0+
HIGH 7.5
CVE-2020-29043
An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can cr…
Bigbluebutton
after 2.2.29
MEDIUM 5.3
CVE-2020-28954
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control charac…
Bigbluebutton
2.2.29+
MEDIUM 6.1
CVE-2020-27642
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
Greenlight
Patch available
CRITICAL 9.8
CVE-2020-27605
BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schw…
Bigbluebutton
after 2.2.28
HIGH 8.4
CVE-2020-27613
The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve u…
Bigbluebutton
2.2.28+
HIGH 7.5
CVE-2020-27610
The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not automati…
Bigbluebutton
2.2.28+