Org.apache.openmeetings:openmeetings-parent
This hub aggregates every CVE we track for Org.apache.openmeetings:openmeetings-parent, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
22
CVEs tracked
5
Critical
12
High
0
In CISA KEV
Severity distribution
HIGH12MEDIUM5CRITICAL5
Monthly trend
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Org.apache.openmeetings:openmeetings-parent.
- CVE-2024-54676Apache OpenMeetings: Deserialisation of untrusted data in cluster mode9.8
- CVE-2023-29032Apache OpenMeetings: allows bypass authentication8.1
- CVE-2023-29246Apache OpenMeetings: allows null-byte Injection7.2
- CVE-2023-28326Apache OpenMeetings: allows user impersonation9.8
- CVE-2021-27576Apache OpenMeetings: bandwidth can be overloaded with public web service7.5
- CVE-2020-13951Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.7.5
- CVE-2018-1286In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.6.5
- CVE-2016-8736Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.9.8
- CVE-2017-7680Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.7.5
- CVE-2017-7663Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.6.1
- CVE-2017-7664Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.10.0
- CVE-2017-7688Apache OpenMeetings 1.0.0 updates user password in insecure manner.7.5
- CVE-2017-7673Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.9.8
- CVE-2017-7685Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.5.3
- CVE-2017-7681Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the app...8.8
Product normalization is registry-driven with AI assist and human review. How it works