Vulnerabilities > Jitsi > Meet

DATE CVE VULNERABILITY TITLE RISK
2021-04-14 CVE-2021-26812 Cross-site Scripting vulnerability in Jitsi Meet
Cross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module.
network
low complexity
jitsi CWE-79
6.1
2020-04-17 CVE-2020-11878 Use of Hard-coded Credentials vulnerability in Jitsi Meet
The Jitsi Meet (aka docker-jitsi-meet) stack on Docker before stable-4384-1 uses default passwords (such as passw0rd) for system accounts.
network
low complexity
jitsi CWE-798
critical
9.8