bigbluebutton
Communicationsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting bigbluebutton.
- CVE-2026-55489BigBlueButton: IDOR on BBB through /api/graphql via POST parameter "presentationId" leads to Authentication Bypass4.9
- CVE-2026-55491BigBlueButton: Stored XSS in Screenshare Recording Playback via Unescaped Meeting Name5.4
- CVE-2026-46355BigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUser7.1
- CVE-2026-46682BigBlueButton: Blind SQL Injection AUTH (Moderator)8.5
- CVE-2026-46353BigBlueButton API checksum bypass via presentationUploadExternalUrl8.1
- CVE-2026-46404BigBlueButton: Presentation URL Security Hardening6.8
- CVE-2026-46351BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate them8.1
- CVE-2026-27737BigBlueButton has Stored XSS in bbb-playback replay6.5
- CVE-2026-41127BigBlueButton's missing authorization allows viewer to inject/overwrite captions6.5
- CVE-2026-41126BigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL"4.3
- CVE-2026-27736BigBlueButton has Open Redirect vulnerability in ApiController6.1
- CVE-2026-27467BigBlueButton: Audio from participants to the server initially unmuted2.0
- CVE-2026-27466BigBlueButton: Exposed ClamAV port enables Denial of Service7.2
- CVE-2025-61602BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId7.5
- CVE-2025-61601BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation7.5