vciy

CVEs we hold for Bigbluebutton

Records whose assigning authority named Bigbluebutton as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-55491BigBlueButton: Stored XSS in Screenshare Recording Playback via Unescaped Meeting Namebigbluebutton
CVE-2026-55489BigBlueButton: IDOR on BBB through /api/graphql via POST parameter "presentationId" leads to Authentication Bypassbigbluebutton
CVE-2026-46682BigBlueButton: Blind SQL Injection AUTH (Moderator)bigbluebutton
CVE-2026-46404BigBlueButton: Presentation URL Security Hardeningbigbluebutton
CVE-2026-46355BigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUserbigbluebutton
CVE-2026-46353BigBlueButton API checksum bypass via presentationUploadExternalUrlbigbluebutton
CVE-2026-46351BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate thembigbluebutton
CVE-2026-41127BigBlueButton's missing authorization allows viewer to inject/overwrite captionsbigbluebutton
CVE-2026-41126BigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL"bigbluebutton
CVE-2026-27737BigBlueButton has Stored XSS in bbb-playback replaybigbluebutton; blindsidenetworks scalite…
CVE-2026-27736BigBlueButton has Open Redirect vulnerability in ApiControllerbigbluebutton
CVE-2026-27467BigBlueButton: Audio from participants to the server initially unmutedbigbluebutton
CVE-2026-27466BigBlueButton: Exposed ClamAV port enables Denial of Servicebigbluebutton
CVE-2025-61602BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiIdbigbluebutton
CVE-2025-61601BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutationbigbluebutton
CVE-2025-55200BigBlueButton vulnerable to Stored XSS via name of user at Shared Notesbigbluebutton
CVE-2024-39302Some bbb-record-core files installed with wrong file permissionbigbluebutton
CVE-2024-38518bbb-web API additional parameters consideredbigbluebutton
CVE-2023-43798BigBlueButton Blind SSRF When Uploading Presentation (mitigation bypass)bigbluebutton
CVE-2023-43797BigBlueButton Stored Cross-site Scripting vulnerability at Guest Lobbybigbluebutton
CVE-2023-42804BigBlueButton Path Traversal – Reading Certain File Extensionsbigbluebutton
CVE-2023-42803BigBlueButton Unrestricted File Upload vulnerabilitybigbluebutton
CVE-2023-33176Blind SSRF When Uploading Presentation in BigBlueButtonbigbluebutton
CVE-2022-41964BigBlueButton contains Response leaks in anonymous pollsbigbluebutton
CVE-2022-41963BigBlueButton contains Improper Preservation of Permissions for whiteboardbigbluebutton
CVE-2022-41962BigBlueButton contains Incorrect Authorization for setting emoji statusbigbluebutton
CVE-2022-41961BigBlueButton subject to Ineffective user bansbigbluebutton
CVE-2022-41960BigBlueButton contains DoS via failed authToken validationbigbluebutton
CVE-2022-36029BigBlueButton Greenlight Open Redirect vulnerabilitybigbluebutton greenlight
CVE-2022-36028BigBlueButton Greenlight Open Redirect vulnerabilitybigbluebutton greenlight
CVE-2022-31065Cross site scripting vulnerability for private chat in bigbluebuttonbigbluebutton
CVE-2022-31064Cross site scripting in username that will trigger by sending chatbigbluebutton
CVE-2022-31039Improper privilege management - Anyone can view room settings in GreenLightbigbluebutton greenlight
CVE-2022-29236Improper access control for pencil annotations in BigBlueButtonbigbluebutton
CVE-2022-29235Limited data exposure for shared external videos in BigBlueButtonbigbluebutton
CVE-2022-29234Grace period for lock settings in public/private chats in BigBlueButtonbigbluebutton
CVE-2022-29233Improper access control for breakout rooms in BigBlue Buttonbigbluebutton
CVE-2022-29232Exposure of messages in BigBlueButton public chatsbigbluebutton
CVE-2022-29169ReDoS on endpoint html5client/useragent in BigBlueButtonbigbluebutton
CVE-2022-23490Improper access control to polling votesbigbluebutton
CVE-2022-23488BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Databigbluebutton
CVE-2021-4143Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebuttonbigbluebutton/bigbluebutton

42 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.