Vulnerabilidades en TrueConf
11 resultadosAnálisis Vexday
TrueConf apresenta 11 vulnerabilidades catalogadas, com 1 atualmente sob exploração ativa e 1 classificada como crítica, indicando presença real em cenários de ataque. A ausência de divulgações nos últimos 90 dias sugere que o risco é consolidado e não em expansão recente. A fraqueza dominante (CWE-80, Improper Neutralization of Script-Related HTML Tags) aponta para vetores de XSS, típicos em plataformas de comunicação.
CVE-2026-3502HIGHTrueConf Client Update Integrity Verification BypassEPSS 5.8%KEVCVE-2022-46764CRITICALA SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to executEPSS 2.1%CVE-2022-46763HIGHA SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database uEPSS 1.0%CVE-2017-20119LOWTrueConf Server change-lang redirectEPSS 0.7%CVE-2017-20115LOWTrueConf Server Reflected cross site scriptingEPSS 0.6%CVE-2017-20117LOWTrueConf Server group DOM cross site scriptingEPSS 0.6%CVE-2017-20118LOWTrueConf Server DOM cross site scriptingEPSS 0.6%CVE-2017-20114LOWTrueConf Server Reflected cross site scriptingEPSS 0.6%CVE-2017-20113LOWTrueConf Server Stored cross site scriptingEPSS 0.6%CVE-2017-20116LOWTrueConf Server Reflected cross site scriptingEPSS 0.6%CVE-2017-20120MEDIUMTrueConf Server cross-site request forgeryEPSS 0.5%