Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bigbluebutton MEDIUM 6.1
CVE-2026-27736

BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks val…

Fix: 3.0.20+
Fix from $1,600 2026-02-25
Bigbluebutton HIGH 8.2
CVE-2026-27466

BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for…

Fix: 3.0.22+
Fix from $1,950 2026-02-21
Bigbluebutton HIGH 7.5
CVE-2025-61601

BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user …

Fix: 3.0.13+
Fix from $1,950 2025-10-09
Bigbluebutton HIGH 7.5
CVE-2025-61602

BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user …

Fix: 3.0.13+
Fix from $1,950 2025-10-09
Bigbluebutton MEDIUM 5.4
CVE-2025-55200

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XS…

Fix: 3.0.13+
Fix from $1,600 2025-10-09
Greenlight MEDIUM 6.1
CVE-2022-36028

Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to …

Fix: 2.13.0+
Fix from $1,600 2024-04-25
Greenlight MEDIUM 6.1
CVE-2022-36029

Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to …

Fix: 2.13.0+
Fix from $1,600 2024-04-25
Bigbluebutton MEDIUM 5.4
CVE-2023-43797

BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when…

Fix: 2.6.11+
Fix from $1,600 2023-10-30
Bigbluebutton MEDIUM 5.4
CVE-2023-43798

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery…

Fix: 2.6.12+
Fix from $1,600 2023-10-30
Bigbluebutton MEDIUM 5.3
CVE-2023-42804

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an atta…

Fix: after 2.5.18
Fix from $1,600 2023-10-30
Bigbluebutton HIGH 8.8
CVE-2023-42803

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the i…

Fix: after 2.5.18
Fix from $1,950 2023-10-30
Bigbluebutton MEDIUM 6.5
CVE-2023-33176

BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-S…

Fix: 2.5.18 / 2.6.9+
Fix from $1,600 2023-06-26
Bigbluebutton HIGH 7.5
CVE-2022-23488

BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Da…

Fix: 2.4+
Fix from $1,950 2022-12-17
Bigbluebutton MEDIUM 5.7
CVE-2022-41964

BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can st…

Patch available
Fix from $1,600 2022-12-16
Bigbluebutton CRITICAL 9.8
CVE-2020-27602

BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

Fix: 2.2.7+
Fix from $2,300 2022-09-29
Bigbluebutton MEDIUM 6.1
CVE-2022-31065

BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it execut…

Fix: 2.4.8+
Fix from $1,600 2022-06-27
Bigbluebutton MEDIUM 5.4
CVE-2022-31064

BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack …

Fix: 2.4.8+
Fix from $1,600 2022-06-27
Greenlight MEDIUM 5.3
CVE-2022-31039

Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though t…

Fix: 2.12.6+
Fix from $1,600 2022-06-27
Bigbluebutton MEDIUM 5.4
CVE-2022-27238

BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could i…

Fix: after 2.4.7
Fix from $1,600 2022-06-24
Greenlight MEDIUM 5.4
CVE-2022-26497

BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the br…

Patch available
Fix from $1,600 2022-06-02
Bigbluebutton MEDIUM 5.3
CVE-2022-29235

BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able t…

Fix: 2.3.18+
Fix from $1,600 2022-06-02
Bigbluebutton MEDIUM 6.5
CVE-2022-29232

BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circum…

Fix: 2.3.9+
Fix from $1,600 2022-06-01
Bigbluebutton HIGH 7.5
CVE-2022-29169

BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to re…

Fix: 2.3.19 / 2.4.7+
Fix from $1,950 2022-06-01
Bigbluebutton MEDIUM 6.1
CVE-2021-4143

Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.

Fix: 2.4.0+
Fix from $1,600 2022-01-19
Bigbluebutton HIGH 7.5
CVE-2020-29043

An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can cr…

Fix: after 2.2.29
Fix from $1,950 2020-11-26
Bigbluebutton MEDIUM 5.3
CVE-2020-28954

web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control charac…

Fix: 2.2.29+
Fix from $1,600 2020-11-19
Greenlight MEDIUM 6.1
CVE-2020-27642

A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.

Patch available
Fix from $1,600 2020-10-22
Bigbluebutton CRITICAL 9.8
CVE-2020-27605

BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schw…

Fix: after 2.2.28
Fix from $2,300 2020-10-21
Bigbluebutton HIGH 8.4
CVE-2020-27613

The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve u…

Fix: 2.2.28+
Fix from $1,950 2020-10-21
Bigbluebutton HIGH 7.5
CVE-2020-27610

The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not automati…

Fix: 2.2.28+
Fix from $1,950 2020-10-21