Apache openmeetings
This hub aggregates every CVE we track for Apache openmeetings, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
23
CVEs tracked
5
Critical
12
High
0
In CISA KEV
Severity distribution
HIGH12MEDIUM6CRITICAL5
Monthly trend
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
3
0
0
1
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Apache openmeetings.
- CVE-2026-49488Apache OpenMeetings: Arbitrary File Read6.5
- CVE-2026-33005Apache OpenMeetings: Insufficient checks in FileWebService4.3
- CVE-2026-33266Apache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and Salt7.5
- CVE-2026-34020Apache OpenMeetings: Login Credentials Passed via GET Query Parameters7.5
- CVE-2024-54676Apache OpenMeetings: Deserialisation of untrusted data in cluster mode9.8
- CVE-2023-28936Apache OpenMeetings: insufficient check of invitation hash5.3
- CVE-2023-29032Apache OpenMeetings: allows bypass authentication8.1
- CVE-2023-29246Apache OpenMeetings: allows null-byte Injection7.2
- CVE-2023-28326Apache OpenMeetings: allows user impersonation9.8
- CVE-2021-27576Apache OpenMeetings: bandwidth can be overloaded with public web service7.5
- CVE-2018-1286In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.6.5
- CVE-2016-8736Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.9.8
- CVE-2017-7680Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.7.5
- CVE-2017-7663Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.6.1
- CVE-2017-7664Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.10.0
Product normalization is registry-driven with AI assist and human review. How it works