Vulnerabilidades en bigbluebutton
38 resultadosAnálisis Vexday
BigBlueButton apresenta 38 vulnerabilidades catalogadas, com 2 classificadas como críticas, mas nenhuma sob exploração ativa documentada. A fraqueza dominante é exposição de informações (CWE-200), padrão recorrente que demanda revisão de controles de acesso e vazamento de dados; 4 vulnerabilidades publicadas nos últimos 90 dias indicam descobertas contínuas que justificam monitoramento ativo.
CVE-2023-43798MEDIUMBigBlueButton Blind SSRF When Uploading Presentation (mitigation bypass)EPSS 0.4%CVE-2022-41963LOWBigBlueButton contains Improper Preservation of Permissions for whiteboardEPSS 0.4%CVE-2022-36029CRITICALBigBlueButton Greenlight Open Redirect vulnerabilityEPSS 0.4%CVE-2026-27466HIGHBigBlueButton: Exposed ClamAV port enables Denial of ServiceEPSS 0.4%CVE-2025-61602HIGHBigBlueButton vulnerable to Chat DoS via invalid reactionEmojiIdEPSS 0.4%CVE-2022-36028CRITICALBigBlueButton Greenlight Open Redirect vulnerabilityEPSS 0.4%CVE-2022-41960MEDIUMBigBlueButton contains DoS via failed authToken validationEPSS 0.4%CVE-2024-38518MEDIUMbbb-web API additional parameters consideredEPSS 0.3%CVE-2022-41961MEDIUMBigBlueButton subject to Ineffective user bansEPSS 0.3%CVE-2026-46353HIGHBigBlueButton API checksum bypass via presentationUploadExternalUrlEPSS 0.3%CVE-2026-46351HIGHBigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate themEPSS 0.3%CVE-2026-27737MEDIUMBigBlueButton has Stored XSS in bbb-playback replayEPSS 0.3%CVE-2026-46404MEDIUMBigBlueButton: Presentation URL Security HardeningEPSS 0.3%CVE-2026-41126MEDIUMBigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL"EPSS 0.2%CVE-2025-55200HIGHBigBlueButton vulnerable to Stored XSS via name of user at Shared NotesEPSS 0.2%CVE-2026-41127MEDIUMBigBlueButton's missing authorization allows viewer to inject/overwrite captionsEPSS 0.2%CVE-2026-27467LOWBigBlueButton: Audio from participants to the server initially unmutedEPSS 0.2%CVE-2026-27736MEDIUMBigBlueButton has Open Redirect vulnerability in ApiControllerEPSS 0.1%