Vulnerabilities in bigbluebutton

42 results
Vexday analysis

BigBlueButton apresenta 38 vulnerabilidades catalogadas, com 2 classificadas como críticas, mas nenhuma sob exploração ativa documentada. A fraqueza dominante é exposição de informações (CWE-200), padrão recorrente que demanda revisão de controles de acesso e vazamento de dados; 4 vulnerabilidades publicadas nos últimos 90 dias indicam descobertas contínuas que justificam monitoramento ativo.

CVE-2022-29169HIGHReDoS on endpoint html5client/useragent in BigBlueButtonEPSS 1.5%CVE-2022-31064MEDIUMCross site scripting in username that will trigger by sending chatEPSS 1.3%CVE-2022-29232MEDIUMExposure of messages in BigBlueButton public chatsEPSS 1.0%CVE-2022-29235MEDIUMLimited data exposure for shared external videos in BigBlueButtonEPSS 1.0%CVE-2022-29233MEDIUMImproper access control for breakout rooms in BigBlue ButtonEPSS 1.0%CVE-2021-4143HIGHCross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebuttonEPSS 0.9%CVE-2022-29236MEDIUMImproper access control for pencil annotations in BigBlueButtonEPSS 0.9%CVE-2022-29234MEDIUMGrace period for lock settings in public/private chats in BigBlueButtonEPSS 0.8%CVE-2022-31065MEDIUMCross site scripting vulnerability for private chat in bigbluebuttonEPSS 0.8%CVE-2022-31039MEDIUMImproper privilege management - Anyone can view room settings in GreenLightEPSS 0.7%CVE-2022-41962LOWBigBlueButton contains Incorrect Authorization for setting emoji statusEPSS 0.7%CVE-2022-23488MEDIUMBigBlueButton vulnerable to Insertion of Sensitive Information Into Sent DataEPSS 0.6%CVE-2026-27466HIGHBigBlueButton: Exposed ClamAV port enables Denial of ServiceEPSS 0.6%CVE-2026-46682HIGHBigBlueButton: Blind SQL Injection AUTH (Moderator)EPSS 0.6%CVE-2022-41964MEDIUMBigBlueButton contains Response leaks in anonymous pollsEPSS 0.6%CVE-2023-42803MEDIUMBigBlueButton Unrestricted File Upload vulnerabilityEPSS 0.5%CVE-2026-46353HIGHBigBlueButton API checksum bypass via presentationUploadExternalUrlEPSS 0.5%CVE-2025-61601HIGHBigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutationEPSS 0.5%CVE-2023-33176MEDIUMBlind SSRF When Uploading Presentation in BigBlueButtonEPSS 0.5%CVE-2026-46351HIGHBigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate themEPSS 0.5%