CVEs we hold for Bigbluebutton
Records whose assigning authority named Bigbluebutton as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-55491BigBlueButton: Stored XSS in Screenshare Recording Playback via Unescaped Meeting Namebigbluebutton CVE-2026-55489BigBlueButton: IDOR on BBB through /api/graphql via POST parameter "presentationId" leads to Authentication Bypassbigbluebutton CVE-2026-46682BigBlueButton: Blind SQL Injection AUTH (Moderator)bigbluebutton CVE-2026-46404BigBlueButton: Presentation URL Security Hardeningbigbluebutton CVE-2026-46355BigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUserbigbluebutton CVE-2026-46353BigBlueButton API checksum bypass via presentationUploadExternalUrlbigbluebutton CVE-2026-46351BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate thembigbluebutton CVE-2026-41127BigBlueButton's missing authorization allows viewer to inject/overwrite captionsbigbluebutton CVE-2026-41126BigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL"bigbluebutton CVE-2026-27737BigBlueButton has Stored XSS in bbb-playback replaybigbluebutton; blindsidenetworks scalite… CVE-2026-27736BigBlueButton has Open Redirect vulnerability in ApiControllerbigbluebutton CVE-2026-27467BigBlueButton: Audio from participants to the server initially unmutedbigbluebutton CVE-2026-27466BigBlueButton: Exposed ClamAV port enables Denial of Servicebigbluebutton CVE-2025-61602BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiIdbigbluebutton CVE-2025-61601BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutationbigbluebutton CVE-2025-55200BigBlueButton vulnerable to Stored XSS via name of user at Shared Notesbigbluebutton CVE-2024-39302Some bbb-record-core files installed with wrong file permissionbigbluebutton CVE-2024-38518bbb-web API additional parameters consideredbigbluebutton CVE-2023-43798BigBlueButton Blind SSRF When Uploading Presentation (mitigation bypass)bigbluebutton CVE-2023-43797BigBlueButton Stored Cross-site Scripting vulnerability at Guest Lobbybigbluebutton CVE-2023-42804BigBlueButton Path Traversal – Reading Certain File Extensionsbigbluebutton CVE-2023-42803BigBlueButton Unrestricted File Upload vulnerabilitybigbluebutton CVE-2023-33176Blind SSRF When Uploading Presentation in BigBlueButtonbigbluebutton CVE-2022-41964BigBlueButton contains Response leaks in anonymous pollsbigbluebutton CVE-2022-41963BigBlueButton contains Improper Preservation of Permissions for whiteboardbigbluebutton CVE-2022-41962BigBlueButton contains Incorrect Authorization for setting emoji statusbigbluebutton CVE-2022-41961BigBlueButton subject to Ineffective user bansbigbluebutton CVE-2022-41960BigBlueButton contains DoS via failed authToken validationbigbluebutton CVE-2022-36029BigBlueButton Greenlight Open Redirect vulnerabilitybigbluebutton greenlight CVE-2022-36028BigBlueButton Greenlight Open Redirect vulnerabilitybigbluebutton greenlight CVE-2022-31065Cross site scripting vulnerability for private chat in bigbluebuttonbigbluebutton CVE-2022-31064Cross site scripting in username that will trigger by sending chatbigbluebutton CVE-2022-31039Improper privilege management - Anyone can view room settings in GreenLightbigbluebutton greenlight CVE-2022-29236Improper access control for pencil annotations in BigBlueButtonbigbluebutton CVE-2022-29235Limited data exposure for shared external videos in BigBlueButtonbigbluebutton CVE-2022-29234Grace period for lock settings in public/private chats in BigBlueButtonbigbluebutton CVE-2022-29233Improper access control for breakout rooms in BigBlue Buttonbigbluebutton CVE-2022-29232Exposure of messages in BigBlueButton public chatsbigbluebutton CVE-2022-29169ReDoS on endpoint html5client/useragent in BigBlueButtonbigbluebutton CVE-2022-23488BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Databigbluebutton CVE-2021-4143Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebuttonbigbluebutton/bigbluebutton 42 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.