CVE-2025-64754
- EPSS 0.18%
- Veröffentlicht 13.11.2025 21:48:08
- Zuletzt bearbeitet 14.11.2025 16:42:03
Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the OAuth authentication window for Microsoft accounts. This is fixed in version 2.0.10532. No known workar...
CVE-2024-44080
- EPSS 0.16%
- Veröffentlicht 29.10.2024 22:15:03
- Zuletzt bearbeitet 10.07.2025 19:33:11
In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from any arbitrary URL if a message from another participant contains a URL encoded in the expected f...
CVE-2024-44081
- EPSS 0.33%
- Veröffentlicht 29.10.2024 22:15:03
- Zuletzt bearbeitet 10.07.2025 19:34:16
In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an arbitrary URL if a message from another participant contains a URL encoded in the expected format.
CVE-2024-33530
- EPSS 0.13%
- Veröffentlicht 02.05.2024 16:15:08
- Zuletzt bearbeitet 20.03.2025 20:15:32
In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.
CVE-2021-26812
- EPSS 18.99%
- Veröffentlicht 14.04.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:56:51
Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers to craft a malicious URL, which when clicked on by users, can inject javascript code to be run by the application...
CVE-2020-11878
- EPSS 0.36%
- Veröffentlicht 17.04.2020 16:15:14
- Zuletzt bearbeitet 21.11.2024 04:58:48
The Jitsi Meet (aka docker-jitsi-meet) stack on Docker before stable-4384-1 uses default passwords (such as passw0rd) for system accounts.