Bigbluebutton
Bigbluebutton: vulnerabilidades y CVE
Bigbluebutton tiene 63 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE63
Últimos 12 meses17
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-55491 | Media (5.4) | 0.29% | — | 20 ago 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format.… |
| CVE-2026-55489 | Media (4.9) | 0.31% | — | 20 ago 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another meeting.… |
| CVE-2026-46682 | Alta (8.5) | 0.58% | — | 20 ago 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in… |
| CVE-2026-46355 | Alta (7.1) | 0.37% | — | 20 ago 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through… |
| CVE-2026-71555 | Media (4.1) | 0.29% | — | 6 ago 2026 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that… |
| CVE-2026-46404 | Media (6.8) | 0.43% | — | 16 jul 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. The redirect following logic now pins resolved… |
| CVE-2026-46353 | Alta (8.1) | 0.48% | — | 16 jul 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java… |
| CVE-2026-46351 | Alta (8.1) | 0.46% | — | 16 jul 2026 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java… |
| CVE-2026-27737 | Media (6.5) | 0.43% | — | 18 may 2026 | BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicious actor to craft… |
| CVE-2026-41127 | Media (6.5) | 0.30% | — | 22 abr 2026 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit… |
| CVE-2026-41126 | Media (4.3) | 0.28% | — | 22 abr 2026 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with… |
| CVE-2026-27736 | Media (6.1) | 0.26% | — | 25 feb 2026 | BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads… |
| CVE-2026-27467 | Baja (2.4) | 0.28% | — | 21 feb 2026 | BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the microphone muted, the client sends audio to the server regardless of mute state. Media is discarded… |
| CVE-2026-27466 | Alta (8.2) | 0.58% | — | 21 feb 2026 | BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains instructions that leave… |
| CVE-2025-61602 | Alta (7.5) | 0.39% | — | 9 oct 2025 | BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for all participants in a meeting by… |
| CVE-2025-61601 | Alta (7.5) | 0.47% | — | 9 oct 2025 | BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's… |
| CVE-2025-55200 | Media (5.4) | 0.24% | — | 9 oct 2025 | BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XSS) vulnerability with the input location being the "Username" field… |
| CVE-2023-7296 | Media (6.4) | 0.29% | — | 16 oct 2024 | The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewer code fields in versions up to, and including, 3.0.0-beta.4 due to insufficient input sanitization… |
| CVE-2024-39302 | Baja (3.7) | 0.45% | — | 28 jun 2024 | BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the… |
| CVE-2024-38518 | Media (4.6) | 0.31% | — | 28 jun 2024 | BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with… |
| CVE-2023-43798 | Media (5.4) | 0.42% | — | 30 oct 2023 | BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions… |
| CVE-2023-43797 | Media (5.4) | 0.42% | — | 30 oct 2023 | BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages… |
| CVE-2023-42804 | Media (5.3) | 0.46% | — | 30 oct 2023 | BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other… |
| CVE-2023-42803 | Alta (8.8) | 0.54% | — | 30 oct 2023 | BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension… |
| CVE-2023-33176 | Media (6.5) | 0.47% | — | 26 jun 2023 | BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API… |
| CVE-2022-23488 | Alta (7.5) | 0.60% | — | 17 dic 2022 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Data. The moderators-only webcams lock setting is not enforced on the… |
| CVE-2022-23490 | Media (4.3) | 0.46% | — | 16 dic 2022 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant.… |
| CVE-2022-41964 | Media (5.7) | 0.58% | — | 16 dic 2022 | BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll,… |
| CVE-2022-41963 | Baja (3.1) | 0.44% | — | 16 dic 2022 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions… |
| CVE-2022-41962 | Baja (2.7) | 0.69% | — | 16 dic 2022 | BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect Authorization for setting emoji status. A user with moderator rights can use the clear status… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.