<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – BigBlueButton (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/bigbluebutton.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/bigbluebutton-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – BigBlueButton (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:45 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-27466 – BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27466</guid>
    <pubDate>Sat, 21 Feb 2026 08:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27466</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains instructions that leave a BBB server vulnerable for Denial of Service. The flawed command exposes both ports (3310 and 7357) to the internet. A remote attacker can use this to send complex or large docume…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61602 – BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61602</guid>
    <pubDate>Thu, 09 Oct 2025 21:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61602</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for all participants in a meeting by sending a malformed `reactionEmojiId` in the GraphQL mutation `chatSendMessageReaction`. Version 3.0.13 contains a patch. No known workarounds are available.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-703</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61601 – BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61601</guid>
    <pubDate>Thu, 09 Oct 2025 21:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61601</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's `Choices` response type. By submitting a malicious payload with a massive array in the `answerIds` field, the attacker can cause the current meeting — and potentially all meetings…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-703</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55200 – BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55200</guid>
    <pubDate>Thu, 09 Oct 2025 19:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55200</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XSS) vulnerability with the input location being the "Username" field and the output location on the "Shared Notes" page, when a user with a malicious username is editing content. This vulnerability allows a low-privileged user to execute arbitrary Jav…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36029 – Greenlight is an end-user interface for BigBlueButton servers. Versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36029</guid>
    <pubDate>Thu, 25 Apr 2024 21:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36029</strong></p>
  <p>Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36028 – Greenlight is an end-user interface for BigBlueButton servers. Versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36028</guid>
    <pubDate>Thu, 25 Apr 2024 21:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36028</strong></p>
  <p>Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-47107 – PILOS is an open source front-end for BigBlueButton servers with a built-in load...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47107</guid>
    <pubDate>Wed, 08 Nov 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-47107</strong></p>
  <p>PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to PILOS users when so that it points to the attackers server thereby disclosing the password reset token if/when the…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39991 – Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blindside Networks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39991</guid>
    <pubDate>Mon, 04 Sep 2023 11:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39991</strong></p>
  <p>Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blindside Networks BigBlueButton plugin <= 3.0.0-beta.4 versions.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-27602 – BigBlueButton before 2.2.7 does not have a protection mechanism for separator in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27602</guid>
    <pubDate>Thu, 29 Sep 2022 03:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-27602</strong></p>
  <p>BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29169 – BigBlueButton is an open source web conferencing system. Versions starting with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29169</guid>
    <pubDate>Wed, 01 Jun 2022 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29169</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a RegularExpression, an attacker can cause denial of service for the bbb-html5 service. The useragent library performs checking of device by parsing the input of User-Agent header…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-29043 – An issue was discovered in BigBlueButton through 2.2.29. When at attacker is abl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29043</guid>
    <pubDate>Thu, 26 Nov 2020 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-29043</strong></p>
  <p>An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27613 – The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses Clue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27613</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27613</strong></p>
  <p>The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27611 – BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27611</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27611</strong></p>
  <p>BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27610 – The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27610</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27610</strong></p>
  <p>The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not automatically set up a firewall configuration to block external access.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-27605 – BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS doc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27605</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-27605</strong></p>
  <p>BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schwache Sandbox."</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27603 – BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27603</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27603</strong></p>
  <p>BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26163 – BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26163</guid>
    <pubDate>Wed, 30 Sep 2020 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26163</strong></p>
  <p>BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-12443 – BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files becau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12443</guid>
    <pubDate>Wed, 29 Apr 2020 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-12443</strong></p>
  <p>BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence. This can be leveraged for privilege escalation via a directory traversal to bigbluebutton.properties. NOTE: this issue exists because of an ineffective mitigation to CVE-2020-12112 in which there…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12112 – BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12112</guid>
    <pubDate>Thu, 23 Apr 2020 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12112</strong></p>
  <p>BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12112">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
