CVE-2026-72530
- EPSS 0.34%
- Veröffentlicht 19.08.2026 16:56:53
- Zuletzt bearbeitet 21.08.2026 04:18:15
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute...
CVE-2026-72529
- EPSS 0.28%
- Veröffentlicht 19.08.2026 16:55:14
- Zuletzt bearbeitet 21.08.2026 04:18:15
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
CVE-2025-66834
- EPSS 0.27%
- Veröffentlicht 30.12.2025 00:00:00
- Zuletzt bearbeitet 20.08.2026 18:09:37
A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.
CVE-2025-66824
- EPSS 0.27%
- Veröffentlicht 30.12.2025 00:00:00
- Zuletzt bearbeitet 20.08.2026 18:09:50
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users ...
CVE-2025-66823
- EPSS 0.17%
- Veröffentlicht 30.12.2025 00:00:00
- Zuletzt bearbeitet 20.08.2026 18:09:27
An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Confer...
CVE-2017-20120
- EPSS 0.48%
- Veröffentlicht 29.06.2022 17:15:08
- Zuletzt bearbeitet 20.08.2026 19:14:38
A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The ex...