CVE-2026-27736
- EPSS 0.03%
- Veröffentlicht 25.02.2026 16:27:01
- Zuletzt bearbeitet 27.02.2026 14:06:59
BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads to an Open Redirect vulnerabilit...
CVE-2026-27467
- EPSS 0.03%
- Veröffentlicht 21.02.2026 07:18:26
- Zuletzt bearbeitet 26.02.2026 18:54:09
BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the microphone muted, the client sends audio to the server regardless of mute state. Media is discarded at the server side, so it isn't...
CVE-2026-27466
- EPSS 0.11%
- Veröffentlicht 21.02.2026 07:14:49
- Zuletzt bearbeitet 26.02.2026 18:59:18
BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains instructions that leave a BBB server vulnerable for Den...
CVE-2025-61602
- EPSS 0.1%
- Veröffentlicht 09.10.2025 20:40:04
- Zuletzt bearbeitet 20.10.2025 15:36:03
BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for all participants in a meeting by sending a malformed `reactionEmo...
CVE-2025-61601
- EPSS 0.16%
- Veröffentlicht 09.10.2025 20:29:25
- Zuletzt bearbeitet 20.10.2025 15:33:21
BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's `Choices` response type. By sub...
CVE-2025-55200
- EPSS 0.06%
- Veröffentlicht 09.10.2025 18:51:57
- Zuletzt bearbeitet 20.10.2025 15:30:19
BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XSS) vulnerability with the input location being the "Username" field and the output location on the "S...
CVE-2024-39302
- EPSS 0.15%
- Veröffentlicht 28.06.2024 21:15:03
- Zuletzt bearbeitet 21.11.2024 09:27:25
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the `/usr/local/bigbluebutton/core/vendor/bundle/ruby/2.7.0/gems/resque-2...
CVE-2024-38518
- EPSS 0.09%
- Veröffentlicht 28.06.2024 21:15:03
- Zuletzt bearbeitet 21.11.2024 09:26:09
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. One of those ...
CVE-2023-43798
- EPSS 0.03%
- Veröffentlicht 30.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:24:48
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions 2.6.12 and 2.7.0-rc.1 disabled...
CVE-2023-43797
- EPSS 0.07%
- Veröffentlicht 30.10.2023 23:15:08
- Zuletzt bearbeitet 21.11.2024 08:24:48
BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe in...