bigbluebutton kayıtları
bigbluebutton üreticisine ait 55 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %21,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-285 Improper Authorization3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
55 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-12443İstismar yok | BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filenamebigbluebutton · bigbluebutton · CWE-22 | Kritik9,8 | — | %3,7 | 28 Nis 2020 |
39İzleyin | CVE-2020-27602İstismar yok | BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.bigbluebutton · bigbluebutton · CWE-74 | Kritik9,8 | — | %1,4 | 28 Eyl 2022 |
39İzleyin | CVE-2020-27605İstismar yok | BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related tbigbluebutton · bigbluebutton | Kritik9,8 | — | %1,2 | 21 Eki 2020 |
35İzleyin | CVE-2020-26163İstismar yok | BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim followsbigbluebutton · greenlight | Yüksek8,8 | — | %1,5 | 30 Eyl 2020 |
35İzleyin | CVE-2023-42803İstismar yok | BigBlueButton Unrestricted File Upload vulnerabilitybigbluebutton · bigbluebutton · CWE-434 | Yüksek8,8 | — | %0,5 | 30 Eki 2023 |
33İzleyin | CVE-2020-27613İstismar yok | The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to bigbluebutton · bigbluebutton · CWE-312 | Yüksek8,4 | — | %0,3 | 21 Eki 2020 |
32İzleyin | CVE-2020-12112Kavram kanıtı | BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.bigbluebutton · bigbluebutton · CWE-22 | Yüksek7,5 | — | %5,3 | 23 Nis 2020 |
32İzleyin | CVE-2026-27466İstismar yok | BigBlueButton: Exposed ClamAV port enables Denial of Servicebigbluebutton · bigbluebutton · CWE-668 | Yüksek8,2 | — | %0,6 | 21 Şub 2026 |
31İzleyin | CVE-2020-27603Kavram kanıtı | BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.bigbluebutton · bigbluebutton | Yüksek7,5 | — | %2,9 | 21 Eki 2020 |
30İzleyin | CVE-2022-29169İstismar yok | ReDoS on endpoint html5client/useragent in BigBlueButtonbigbluebutton · bigbluebutton · CWE-20 | Yüksek7,5 | — | %1,5 | 1 Haz 2022 |
30İzleyin | CVE-2020-29043İstismar yok | An issue was discovered in BigBlueButton through 2.2.29.bigbluebutton · bigbluebutton · CWE-200 | Yüksek7,5 | — | %1,5 | 26 Kas 2020 |
30İzleyin | CVE-2020-27610İstismar yok | The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does notbigbluebutton · bigbluebutton | Yüksek7,5 | — | %1,2 | 21 Eki 2020 |
30İzleyin | CVE-2022-23488İstismar yok | BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Databigbluebutton · bigbluebutton · CWE-200 | Yüksek7,5 | — | %0,6 | 16 Ara 2022 |
30İzleyin | CVE-2025-61601İstismar yok | BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutationbigbluebutton · bigbluebutton · CWE-703 | Yüksek7,5 | — | %0,5 | 9 Eki 2025 |
30İzleyin | CVE-2025-61602İstismar yok | BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiIdbigbluebutton · bigbluebutton · CWE-703 | Yüksek7,5 | — | %0,4 | 9 Eki 2025 |
29İzleyin | CVE-2020-25820Kavram kanıtı | BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document thbigbluebutton · bigbluebutton · CWE-918 | Orta6,5 | — | %10,5 | 21 Eki 2020 |
29İzleyin | CVE-2020-27611İstismar yok | BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.bigbluebutton · bigbluebutton · CWE-327 | Yüksek7,3 | — | %0,7 | 21 Eki 2020 |
26İzleyin | CVE-2020-27604İstismar yok | BigBlueButton before 2.3 does not implement LibreOffice sandboxing.bigbluebutton · bigbluebutton · CWE-116 | Orta6,5 | — | %1,1 | 21 Eki 2020 |
26İzleyin | CVE-2022-29232İstismar yok | Exposure of messages in BigBlueButton public chatsbigbluebutton · bigbluebutton · CWE-200 | Orta6,5 | — | %1,0 | 1 Haz 2022 |
26İzleyin | CVE-2020-27607İstismar yok | In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data frobigbluebutton · bigbluebutton | Orta6,5 | — | %0,8 | 21 Eki 2020 |
26İzleyin | CVE-2023-33176İstismar yok | Blind SSRF When Uploading Presentation in BigBlueButtonbigbluebutton · bigbluebutton · CWE-918 | Orta6,5 | — | %0,5 | 26 Haz 2023 |
24İzleyin | CVE-2020-12113İstismar yok | BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.bigbluebutton · bigbluebutton · CWE-79 | Orta6,1 | — | %0,9 | 23 Nis 2020 |
24İzleyin | CVE-2021-4143İstismar yok | Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebuttonbigbluebutton · bigbluebutton · CWE-79 | Orta6,1 | — | %0,9 | 19 Oca 2022 |
24İzleyin | CVE-2020-27608İstismar yok | In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as bigbluebutton · bigbluebutton · CWE-79 | Orta6,1 | — | %0,8 | 21 Eki 2020 |
24İzleyin | CVE-2020-27642İstismar yok | A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.bigbluebutton · greenlight · CWE-79 | Orta6,1 | — | %0,8 | 22 Eki 2020 |
- CVE-2020-1244340Planlayın
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename
KritikCVSS 9,8İstismar yokEPSS %4bigbluebutton · bigbluebutton28 Nis 2020
- CVE-2020-2760239İzleyin
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.
KritikCVSS 9,8İstismar yokEPSS %1bigbluebutton · bigbluebutton28 Eyl 2022
- CVE-2020-2760539İzleyin
BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related t
KritikCVSS 9,8İstismar yokEPSS %1bigbluebutton · bigbluebutton21 Eki 2020
- CVE-2020-2616335İzleyin
BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows
YüksekCVSS 8,8İstismar yokEPSS %2bigbluebutton · greenlight30 Eyl 2020
- CVE-2023-4280335İzleyin
BigBlueButton Unrestricted File Upload vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1bigbluebutton · bigbluebutton30 Eki 2023
- CVE-2020-2761333İzleyin
The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to
YüksekCVSS 8,4İstismar yokEPSS %0bigbluebutton · bigbluebutton21 Eki 2020
- CVE-2020-1211232İzleyin
BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
YüksekCVSS 7,5Kavram kanıtıEPSS %5bigbluebutton · bigbluebutton23 Nis 2020
- CVE-2026-2746632İzleyin
BigBlueButton: Exposed ClamAV port enables Denial of Service
YüksekCVSS 8,2İstismar yokEPSS %1bigbluebutton · bigbluebutton21 Şub 2026
- CVE-2020-2760331İzleyin
BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.
YüksekCVSS 7,5Kavram kanıtıEPSS %3bigbluebutton · bigbluebutton21 Eki 2020
- CVE-2022-2916930İzleyin
ReDoS on endpoint html5client/useragent in BigBlueButton
YüksekCVSS 7,5İstismar yokEPSS %2bigbluebutton · bigbluebutton1 Haz 2022
- CVE-2020-2904330İzleyin
An issue was discovered in BigBlueButton through 2.2.29.
YüksekCVSS 7,5İstismar yokEPSS %1bigbluebutton · bigbluebutton26 Kas 2020
- CVE-2020-2761030İzleyin
The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not
YüksekCVSS 7,5İstismar yokEPSS %1bigbluebutton · bigbluebutton21 Eki 2020
- CVE-2022-2348830İzleyin
BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Data
YüksekCVSS 7,5İstismar yokEPSS %1bigbluebutton · bigbluebutton16 Ara 2022
- CVE-2025-6160130İzleyin
BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation
YüksekCVSS 7,5İstismar yokEPSS %0bigbluebutton · bigbluebutton9 Eki 2025
- CVE-2025-6160230İzleyin
BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId
YüksekCVSS 7,5İstismar yokEPSS %0bigbluebutton · bigbluebutton9 Eki 2025
- CVE-2020-2582029İzleyin
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document th
OrtaCVSS 6,5Kavram kanıtıEPSS %10bigbluebutton · bigbluebutton21 Eki 2020
- CVE-2020-2761129İzleyin
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
YüksekCVSS 7,3İstismar yokEPSS %1bigbluebutton · bigbluebutton21 Eki 2020
- CVE-2020-2760426İzleyin
BigBlueButton before 2.3 does not implement LibreOffice sandboxing.
OrtaCVSS 6,5İstismar yokEPSS %1bigbluebutton · bigbluebutton21 Eki 2020
- CVE-2022-2923226İzleyin
Exposure of messages in BigBlueButton public chats
OrtaCVSS 6,5İstismar yokEPSS %1bigbluebutton · bigbluebutton1 Haz 2022
- CVE-2020-2760726İzleyin
In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data fro
OrtaCVSS 6,5İstismar yokEPSS %1bigbluebutton · bigbluebutton21 Eki 2020
- CVE-2023-3317626İzleyin
Blind SSRF When Uploading Presentation in BigBlueButton
OrtaCVSS 6,5İstismar yokEPSS %0bigbluebutton · bigbluebutton26 Haz 2023
- CVE-2020-1211324İzleyin
BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.
OrtaCVSS 6,1İstismar yokEPSS %1bigbluebutton · bigbluebutton23 Nis 2020
- CVE-2021-414324İzleyin
Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebutton
OrtaCVSS 6,1İstismar yokEPSS %1bigbluebutton · bigbluebutton19 Oca 2022
- CVE-2020-2760824İzleyin
In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as
OrtaCVSS 6,1İstismar yokEPSS %1bigbluebutton · bigbluebutton21 Eki 2020
- CVE-2020-2764224İzleyin
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
OrtaCVSS 6,1İstismar yokEPSS %1bigbluebutton · greenlight22 Eki 2020