bigbluebutton records
55 published records for vendor bigbluebutton.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 21.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-285 Improper Authorization3
The weakness classes this vendor ships most often: where to look.
CWEAll records
55 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-12443No exploit | BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filenamebigbluebutton · bigbluebutton · CWE-22 | Critical9.8 | — | 3.7% | Apr 28, 2020 |
39Monitor | CVE-2020-27602No exploit | BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.bigbluebutton · bigbluebutton · CWE-74 | Critical9.8 | — | 1.4% | Sep 28, 2022 |
39Monitor | CVE-2020-27605No exploit | BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related tbigbluebutton · bigbluebutton | Critical9.8 | — | 1.2% | Oct 21, 2020 |
35Monitor | CVE-2020-26163No exploit | BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim followsbigbluebutton · greenlight | High8.8 | — | 1.5% | Sep 30, 2020 |
35Monitor | CVE-2023-42803No exploit | BigBlueButton Unrestricted File Upload vulnerabilitybigbluebutton · bigbluebutton · CWE-434 | High8.8 | — | 0.5% | Oct 30, 2023 |
33Monitor | CVE-2020-27613No exploit | The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to bigbluebutton · bigbluebutton · CWE-312 | High8.4 | — | 0.3% | Oct 21, 2020 |
32Monitor | CVE-2020-12112Proof of concept | BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.bigbluebutton · bigbluebutton · CWE-22 | High7.5 | — | 5.3% | Apr 23, 2020 |
32Monitor | CVE-2026-27466No exploit | BigBlueButton: Exposed ClamAV port enables Denial of Servicebigbluebutton · bigbluebutton · CWE-668 | High8.2 | — | 0.6% | Feb 21, 2026 |
31Monitor | CVE-2020-27603Proof of concept | BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.bigbluebutton · bigbluebutton | High7.5 | — | 2.9% | Oct 21, 2020 |
30Monitor | CVE-2022-29169No exploit | ReDoS on endpoint html5client/useragent in BigBlueButtonbigbluebutton · bigbluebutton · CWE-20 | High7.5 | — | 1.5% | Jun 1, 2022 |
30Monitor | CVE-2020-29043No exploit | An issue was discovered in BigBlueButton through 2.2.29.bigbluebutton · bigbluebutton · CWE-200 | High7.5 | — | 1.5% | Nov 26, 2020 |
30Monitor | CVE-2020-27610No exploit | The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does notbigbluebutton · bigbluebutton | High7.5 | — | 1.2% | Oct 21, 2020 |
30Monitor | CVE-2022-23488No exploit | BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Databigbluebutton · bigbluebutton · CWE-200 | High7.5 | — | 0.6% | Dec 16, 2022 |
30Monitor | CVE-2025-61601No exploit | BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutationbigbluebutton · bigbluebutton · CWE-703 | High7.5 | — | 0.5% | Oct 9, 2025 |
30Monitor | CVE-2025-61602No exploit | BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiIdbigbluebutton · bigbluebutton · CWE-703 | High7.5 | — | 0.4% | Oct 9, 2025 |
29Monitor | CVE-2020-25820Proof of concept | BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document thbigbluebutton · bigbluebutton · CWE-918 | Medium6.5 | — | 10.5% | Oct 21, 2020 |
29Monitor | CVE-2020-27611No exploit | BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.bigbluebutton · bigbluebutton · CWE-327 | High7.3 | — | 0.7% | Oct 21, 2020 |
26Monitor | CVE-2020-27604No exploit | BigBlueButton before 2.3 does not implement LibreOffice sandboxing.bigbluebutton · bigbluebutton · CWE-116 | Medium6.5 | — | 1.1% | Oct 21, 2020 |
26Monitor | CVE-2022-29232No exploit | Exposure of messages in BigBlueButton public chatsbigbluebutton · bigbluebutton · CWE-200 | Medium6.5 | — | 1.0% | Jun 1, 2022 |
26Monitor | CVE-2020-27607No exploit | In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data frobigbluebutton · bigbluebutton | Medium6.5 | — | 0.8% | Oct 21, 2020 |
26Monitor | CVE-2023-33176No exploit | Blind SSRF When Uploading Presentation in BigBlueButtonbigbluebutton · bigbluebutton · CWE-918 | Medium6.5 | — | 0.5% | Jun 26, 2023 |
24Monitor | CVE-2020-12113No exploit | BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.bigbluebutton · bigbluebutton · CWE-79 | Medium6.1 | — | 0.9% | Apr 23, 2020 |
24Monitor | CVE-2021-4143No exploit | Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebuttonbigbluebutton · bigbluebutton · CWE-79 | Medium6.1 | — | 0.9% | Jan 19, 2022 |
24Monitor | CVE-2020-27608No exploit | In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as bigbluebutton · bigbluebutton · CWE-79 | Medium6.1 | — | 0.8% | Oct 21, 2020 |
24Monitor | CVE-2020-27642No exploit | A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.bigbluebutton · greenlight · CWE-79 | Medium6.1 | — | 0.8% | Oct 22, 2020 |
- CVE-2020-1244340Plan
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename
CriticalCVSS 9.8No exploitEPSS 4%bigbluebutton · bigbluebuttonApr 28, 2020
- CVE-2020-2760239Monitor
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.
CriticalCVSS 9.8No exploitEPSS 1%bigbluebutton · bigbluebuttonSep 28, 2022
- CVE-2020-2760539Monitor
BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related t
CriticalCVSS 9.8No exploitEPSS 1%bigbluebutton · bigbluebuttonOct 21, 2020
- CVE-2020-2616335Monitor
BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows
HighCVSS 8.8No exploitEPSS 2%bigbluebutton · greenlightSep 30, 2020
- CVE-2023-4280335Monitor
BigBlueButton Unrestricted File Upload vulnerability
HighCVSS 8.8No exploitEPSS 1%bigbluebutton · bigbluebuttonOct 30, 2023
- CVE-2020-2761333Monitor
The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to
HighCVSS 8.4No exploitEPSS 0%bigbluebutton · bigbluebuttonOct 21, 2020
- CVE-2020-1211232Monitor
BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
HighCVSS 7.5Proof of conceptEPSS 5%bigbluebutton · bigbluebuttonApr 23, 2020
- CVE-2026-2746632Monitor
BigBlueButton: Exposed ClamAV port enables Denial of Service
HighCVSS 8.2No exploitEPSS 1%bigbluebutton · bigbluebuttonFeb 21, 2026
- CVE-2020-2760331Monitor
BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.
HighCVSS 7.5Proof of conceptEPSS 3%bigbluebutton · bigbluebuttonOct 21, 2020
- CVE-2022-2916930Monitor
ReDoS on endpoint html5client/useragent in BigBlueButton
HighCVSS 7.5No exploitEPSS 2%bigbluebutton · bigbluebuttonJun 1, 2022
- CVE-2020-2904330Monitor
An issue was discovered in BigBlueButton through 2.2.29.
HighCVSS 7.5No exploitEPSS 1%bigbluebutton · bigbluebuttonNov 26, 2020
- CVE-2020-2761030Monitor
The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not
HighCVSS 7.5No exploitEPSS 1%bigbluebutton · bigbluebuttonOct 21, 2020
- CVE-2022-2348830Monitor
BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Data
HighCVSS 7.5No exploitEPSS 1%bigbluebutton · bigbluebuttonDec 16, 2022
- CVE-2025-6160130Monitor
BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation
HighCVSS 7.5No exploitEPSS 0%bigbluebutton · bigbluebuttonOct 9, 2025
- CVE-2025-6160230Monitor
BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId
HighCVSS 7.5No exploitEPSS 0%bigbluebutton · bigbluebuttonOct 9, 2025
- CVE-2020-2582029Monitor
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document th
MediumCVSS 6.5Proof of conceptEPSS 10%bigbluebutton · bigbluebuttonOct 21, 2020
- CVE-2020-2761129Monitor
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
HighCVSS 7.3No exploitEPSS 1%bigbluebutton · bigbluebuttonOct 21, 2020
- CVE-2020-2760426Monitor
BigBlueButton before 2.3 does not implement LibreOffice sandboxing.
MediumCVSS 6.5No exploitEPSS 1%bigbluebutton · bigbluebuttonOct 21, 2020
- CVE-2022-2923226Monitor
Exposure of messages in BigBlueButton public chats
MediumCVSS 6.5No exploitEPSS 1%bigbluebutton · bigbluebuttonJun 1, 2022
- CVE-2020-2760726Monitor
In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data fro
MediumCVSS 6.5No exploitEPSS 1%bigbluebutton · bigbluebuttonOct 21, 2020
- CVE-2023-3317626Monitor
Blind SSRF When Uploading Presentation in BigBlueButton
MediumCVSS 6.5No exploitEPSS 0%bigbluebutton · bigbluebuttonJun 26, 2023
- CVE-2020-1211324Monitor
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
MediumCVSS 6.1No exploitEPSS 1%bigbluebutton · bigbluebuttonApr 23, 2020
- CVE-2021-414324Monitor
Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebutton
MediumCVSS 6.1No exploitEPSS 1%bigbluebutton · bigbluebuttonJan 19, 2022
- CVE-2020-2760824Monitor
In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as
MediumCVSS 6.1No exploitEPSS 1%bigbluebutton · bigbluebuttonOct 21, 2020
- CVE-2020-2764224Monitor
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
MediumCVSS 6.1No exploitEPSS 1%bigbluebutton · greenlightOct 22, 2020