Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-27736 BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks val… Bigbluebutton 3.0.20+ Fix from $1,6002026-02-25 HIGH 8.2 CVE-2026-27466 BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for… Bigbluebutton 3.0.22+ Fix from $1,9502026-02-21 HIGH 7.5 CVE-2025-61601 BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user … Bigbluebutton 3.0.13+ Fix from $1,9502025-10-09 HIGH 7.5 CVE-2025-61602 BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user … Bigbluebutton 3.0.13+ Fix from $1,9502025-10-09 MEDIUM 5.4 CVE-2025-55200 BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XS… Bigbluebutton 3.0.13+ Fix from $1,6002025-10-09 MEDIUM 6.1 CVE-2022-36028 Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to … Greenlight 2.13.0+ Fix from $1,6002024-04-25 MEDIUM 6.1 CVE-2022-36029 Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to … Greenlight 2.13.0+ Fix from $1,6002024-04-25 MEDIUM 5.4 CVE-2023-43797 BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when… Bigbluebutton 2.6.11+ Fix from $1,6002023-10-30 MEDIUM 5.4 CVE-2023-43798 BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery… Bigbluebutton 2.6.12+ Fix from $1,6002023-10-30 MEDIUM 5.3 CVE-2023-42804 BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an atta… Bigbluebutton after 2.5.18 Fix from $1,6002023-10-30 HIGH 8.8 CVE-2023-42803 BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the i… Bigbluebutton after 2.5.18 Fix from $1,9502023-10-30 MEDIUM 6.5 CVE-2023-33176 BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-S… Bigbluebutton 2.5.18 / 2.6.9+ Fix from $1,6002023-06-26 HIGH 7.5 CVE-2022-23488 BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Da… Bigbluebutton 2.4+ Fix from $1,9502022-12-17 MEDIUM 5.7 CVE-2022-41964 BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can st… Bigbluebutton Patch available Fix from $1,6002022-12-16 CRITICAL 9.8 CVE-2020-27602 BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken. Bigbluebutton 2.2.7+ Fix from $2,3002022-09-29 MEDIUM 6.1 CVE-2022-31065 BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it execut… Bigbluebutton 2.4.8+ Fix from $1,6002022-06-27 MEDIUM 5.4 CVE-2022-31064 BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack … Bigbluebutton 2.4.8+ Fix from $1,6002022-06-27 MEDIUM 5.3 CVE-2022-31039 Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though t… Greenlight 2.12.6+ Fix from $1,6002022-06-27 MEDIUM 5.4 CVE-2022-27238 BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could i… Bigbluebutton after 2.4.7 Fix from $1,6002022-06-24 MEDIUM 5.4 CVE-2022-26497 BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the br… Greenlight Patch available Fix from $1,6002022-06-02 MEDIUM 5.3 CVE-2022-29235 BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able t… Bigbluebutton 2.3.18+ Fix from $1,6002022-06-02 MEDIUM 6.5 CVE-2022-29232 BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circum… Bigbluebutton 2.3.9+ Fix from $1,6002022-06-01 HIGH 7.5 CVE-2022-29169 BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to re… Bigbluebutton 2.3.19 / 2.4.7+ Fix from $1,9502022-06-01 MEDIUM 6.1 CVE-2021-4143 Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0. Bigbluebutton 2.4.0+ Fix from $1,6002022-01-19 HIGH 7.5 CVE-2020-29043 An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can cr… Bigbluebutton after 2.2.29 Fix from $1,9502020-11-26 MEDIUM 5.3 CVE-2020-28954 web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control charac… Bigbluebutton 2.2.29+ Fix from $1,6002020-11-19 MEDIUM 6.1 CVE-2020-27642 A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6. Greenlight Patch available Fix from $1,6002020-10-22 CRITICAL 9.8 CVE-2020-27605 BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schw… Bigbluebutton after 2.2.28 Fix from $2,3002020-10-21 HIGH 8.4 CVE-2020-27613 The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve u… Bigbluebutton 2.2.28+ Fix from $1,9502020-10-21 HIGH 7.5 CVE-2020-27610 The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not automati… Bigbluebutton 2.2.28+ Fix from $1,9502020-10-21