Vulnerabilities > Bigbluebutton > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-30 CVE-2023-42803 Unrestricted Upload of File with Dangerous Type vulnerability in Bigbluebutton
BigBlueButton is an open-source virtual classroom.
network
low complexity
bigbluebutton CWE-434
8.8
2022-12-17 CVE-2022-23488 Incorrect Authorization vulnerability in Bigbluebutton
BigBlueButton is an open source web conferencing system.
network
low complexity
bigbluebutton CWE-863
7.5
2022-06-01 CVE-2022-29169 Unspecified vulnerability in Bigbluebutton
BigBlueButton is an open source web conferencing system.
network
low complexity
bigbluebutton
7.5
2020-10-21 CVE-2020-27611 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Bigbluebutton
BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.
network
low complexity
bigbluebutton CWE-327
7.5
2020-10-21 CVE-2020-27605 Unspecified vulnerability in Bigbluebutton
BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schwache Sandbox."
network
low complexity
bigbluebutton
7.5
2020-04-29 CVE-2020-12443 Path Traversal vulnerability in Bigbluebutton
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence.
network
low complexity
bigbluebutton CWE-22
7.5
2020-04-23 CVE-2020-12112 Path Traversal vulnerability in Bigbluebutton
BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
network
low complexity
bigbluebutton CWE-22
7.5