Skip to content
Noroxi

bigbluebutton records

55 published records for vendor bigbluebutton.

All records

55 records
  • BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename

    CriticalCVSS 9.8No exploitEPSS 4%

    bigbluebutton · bigbluebuttonApr 28, 2020

  • BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

    CriticalCVSS 9.8No exploitEPSS 1%

    bigbluebutton · bigbluebuttonSep 28, 2022

  • BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related t

    CriticalCVSS 9.8No exploitEPSS 1%

    bigbluebutton · bigbluebuttonOct 21, 2020

  • BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows

    HighCVSS 8.8No exploitEPSS 2%

    bigbluebutton · greenlightSep 30, 2020

  • BigBlueButton Unrestricted File Upload vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    bigbluebutton · bigbluebuttonOct 30, 2023

  • The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to

    HighCVSS 8.4No exploitEPSS 0%

    bigbluebutton · bigbluebuttonOct 21, 2020

  • BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.

    HighCVSS 7.5Proof of conceptEPSS 5%

    bigbluebutton · bigbluebuttonApr 23, 2020

  • BigBlueButton: Exposed ClamAV port enables Denial of Service

    HighCVSS 8.2No exploitEPSS 1%

    bigbluebutton · bigbluebuttonFeb 21, 2026

  • BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.

    HighCVSS 7.5Proof of conceptEPSS 3%

    bigbluebutton · bigbluebuttonOct 21, 2020

  • ReDoS on endpoint html5client/useragent in BigBlueButton

    HighCVSS 7.5No exploitEPSS 2%

    bigbluebutton · bigbluebuttonJun 1, 2022

  • An issue was discovered in BigBlueButton through 2.2.29.

    HighCVSS 7.5No exploitEPSS 1%

    bigbluebutton · bigbluebuttonNov 26, 2020

  • The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not

    HighCVSS 7.5No exploitEPSS 1%

    bigbluebutton · bigbluebuttonOct 21, 2020

  • BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Data

    HighCVSS 7.5No exploitEPSS 1%

    bigbluebutton · bigbluebuttonDec 16, 2022

  • BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation

    HighCVSS 7.5No exploitEPSS 0%

    bigbluebutton · bigbluebuttonOct 9, 2025

  • BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId

    HighCVSS 7.5No exploitEPSS 0%

    bigbluebutton · bigbluebuttonOct 9, 2025

  • BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document th

    MediumCVSS 6.5Proof of conceptEPSS 10%

    bigbluebutton · bigbluebuttonOct 21, 2020

  • BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.

    HighCVSS 7.3No exploitEPSS 1%

    bigbluebutton · bigbluebuttonOct 21, 2020

  • BigBlueButton before 2.3 does not implement LibreOffice sandboxing.

    MediumCVSS 6.5No exploitEPSS 1%

    bigbluebutton · bigbluebuttonOct 21, 2020

  • Exposure of messages in BigBlueButton public chats

    MediumCVSS 6.5No exploitEPSS 1%

    bigbluebutton · bigbluebuttonJun 1, 2022

  • In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data fro

    MediumCVSS 6.5No exploitEPSS 1%

    bigbluebutton · bigbluebuttonOct 21, 2020

  • Blind SSRF When Uploading Presentation in BigBlueButton

    MediumCVSS 6.5No exploitEPSS 0%

    bigbluebutton · bigbluebuttonJun 26, 2023

  • BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.

    MediumCVSS 6.1No exploitEPSS 1%

    bigbluebutton · bigbluebuttonApr 23, 2020

  • CVE-2021-4143
    24Monitor

    Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebutton

    MediumCVSS 6.1No exploitEPSS 1%

    bigbluebutton · bigbluebuttonJan 19, 2022

  • In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as

    MediumCVSS 6.1No exploitEPSS 1%

    bigbluebutton · bigbluebuttonOct 21, 2020

  • A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.

    MediumCVSS 6.1No exploitEPSS 1%

    bigbluebutton · greenlightOct 22, 2020