« Volver al listado

Bigbluebutton

Bigbluebutton: vulnerabilidades y CVE

Bigbluebutton tiene 63 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE63
Últimos 12 meses17
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-55491Media (5.4)0.29%—20 ago 2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format.…
CVE-2026-55489Media (4.9)0.31%—20 ago 2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another meeting.…
CVE-2026-46682Alta (8.5)0.58%—20 ago 2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in…
CVE-2026-46355Alta (7.1)0.37%—20 ago 2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through…
CVE-2026-71555Media (4.1)0.29%—6 ago 2026
PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that…
CVE-2026-46404Media (6.8)0.43%—16 jul 2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. The redirect following logic now pins resolved…
CVE-2026-46353Alta (8.1)0.48%—16 jul 2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java…
CVE-2026-46351Alta (8.1)0.46%—16 jul 2026
BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java…
CVE-2026-27737Media (6.5)0.43%—18 may 2026
BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicious actor to craft…
CVE-2026-41127Media (6.5)0.30%—22 abr 2026
BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit…
CVE-2026-41126Media (4.3)0.28%—22 abr 2026
BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with…
CVE-2026-27736Media (6.1)0.26%—25 feb 2026
BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads…
CVE-2026-27467Baja (2.4)0.28%—21 feb 2026
BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the microphone muted, the client sends audio to the server regardless of mute state. Media is discarded…
CVE-2026-27466Alta (8.2)0.58%—21 feb 2026
BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains instructions that leave…
CVE-2025-61602Alta (7.5)0.39%—9 oct 2025
BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for all participants in a meeting by…
CVE-2025-61601Alta (7.5)0.47%—9 oct 2025
BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's…
CVE-2025-55200Media (5.4)0.24%—9 oct 2025
BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XSS) vulnerability with the input location being the "Username" field…
CVE-2023-7296Media (6.4)0.29%—16 oct 2024
The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewer code fields in versions up to, and including, 3.0.0-beta.4 due to insufficient input sanitization…
CVE-2024-39302Baja (3.7)0.45%—28 jun 2024
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the…
CVE-2024-38518Media (4.6)0.31%—28 jun 2024
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with…
CVE-2023-43798Media (5.4)0.42%—30 oct 2023
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions…
CVE-2023-43797Media (5.4)0.42%—30 oct 2023
BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages…
CVE-2023-42804Media (5.3)0.46%—30 oct 2023
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other…
CVE-2023-42803Alta (8.8)0.54%—30 oct 2023
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension…
CVE-2023-33176Media (6.5)0.47%—26 jun 2023
BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API…
CVE-2022-23488Alta (7.5)0.60%—17 dic 2022
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Data. The moderators-only webcams lock setting is not enforced on the…
CVE-2022-23490Media (4.3)0.46%—16 dic 2022
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant.…
CVE-2022-41964Media (5.7)0.58%—16 dic 2022
BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll,…
CVE-2022-41963Baja (3.1)0.44%—16 dic 2022
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions…
CVE-2022-41962Baja (2.7)0.69%—16 dic 2022
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect Authorization for setting emoji status. A user with moderator rights can use the clear status…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services4
  2. T1005 Data from Local System1
  3. T1078 Valid Accounts1
  4. T1078.001 Default Accounts1
  5. T1090 Proxy1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Bigbluebutton