<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – BigBlueButton</title>
  <link>https://cvedaily.com/pages/tags/bigbluebutton.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/bigbluebutton.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – BigBlueButton</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:45 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-27737 – BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27737</guid>
    <pubDate>Mon, 18 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27737</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicious actor to craft and carry out a targeted XSS attack, activated on anyone replaying the recording. This issue has been fixed 3.0.19.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41127 – BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41127</guid>
    <pubDate>Wed, 22 Apr 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41127</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41126 – BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41126</guid>
    <pubDate>Wed, 22 Apr 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41126</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that the default logoutURL is used. No known workarounds are available.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27736 – BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27736</guid>
    <pubDate>Wed, 25 Feb 2026 17:25:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27736</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads to an Open Redirect vulnerability. BigBlueButton 3.0.20 patches the issue. No known workarounds are available.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-27467 – BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27467</guid>
    <pubDate>Sat, 21 Feb 2026 08:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-27467</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the microphone muted, the client sends audio to the server regardless of mute state. Media is discarded at the server side, so it isn't audible to any participants, but this may allow for malicious server operators to access audio data. The behavior is only incorrect between joining…</p>
  <p><strong>CVSS:</strong> 2.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27466 – BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27466</guid>
    <pubDate>Sat, 21 Feb 2026 08:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27466</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains instructions that leave a BBB server vulnerable for Denial of Service. The flawed command exposes both ports (3310 and 7357) to the internet. A remote attacker can use this to send complex or large docume…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-22800 – PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22800</guid>
    <pubDate>Mon, 12 Jan 2026 23:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-22800</strong></p>
  <p>PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.10.0, Cross-Site Request Forgery (CSRF) vulnerability exists in an administrative API endpoint responsible for terminating all active video conferences on a single server. The affected endpoint performs a destructive action but is exposed via an HTTP GET request. Although proper authorization checks…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62781 – PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62781</guid>
    <pubDate>Mon, 27 Oct 2025 22:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62781</strong></p>
  <p>PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. Prior to 4.8.0, users with a local account can change their password while logged in. When doing so, all other active sessions are terminated, except for the currently active one. However, the current session’s token remains valid and is not refreshed. If an attacker has previously obtained this session token t…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62524 – PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62524</guid>
    <pubDate>Mon, 27 Oct 2025 21:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62524</strong></p>
  <p>PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 exposes the PHP version via the X-Powered-By header, enabling attackers to fingerprint the server and assess potential exploits. This information disclosure vulnerability originates from PHP’s base image. Additionally, the PHP version can also be inferred through the PILOS version displayed i…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62523 – PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62523</guid>
    <pubDate>Mon, 27 Oct 2025 21:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62523</strong></p>
  <p>PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. PILOS before 4.8.0 includes a Cross-Origin Resource Sharing (CORS) misconfiguration in its middleware: it reflects the Origin request header back in the Access-Control-Allow-Origin response header without proper validation or a whitelist, while Access-Control-Allow-Credentials is set to true. This behavior coul…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-942</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61602 – BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61602</guid>
    <pubDate>Thu, 09 Oct 2025 21:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61602</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to crash the chat functionality for all participants in a meeting by sending a malformed `reactionEmojiId` in the GraphQL mutation `chatSendMessageReaction`. Version 3.0.13 contains a patch. No known workarounds are available.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-703</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61601 – BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61601</guid>
    <pubDate>Thu, 09 Oct 2025 21:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61601</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 allows any authenticated user to freeze or crash the entire server by abusing the polling feature's `Choices` response type. By submitting a malicious payload with a massive array in the `answerIds` field, the attacker can cause the current meeting — and potentially all meetings…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-703</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55200 – BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55200</guid>
    <pubDate>Thu, 09 Oct 2025 19:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55200</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a Stored Cross-Site Scripting (XSS) vulnerability with the input location being the "Username" field and the output location on the "Shared Notes" page, when a user with a malicious username is editing content. This vulnerability allows a low-privileged user to execute arbitrary Jav…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-7296 – The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Script...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7296</guid>
    <pubDate>Wed, 16 Oct 2024 08:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-7296</strong></p>
  <p>The BigBlueButton plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the moderator code and viewer code fields in versions up to, and including, 3.0.0-beta.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with author privileges or higher to inject arbitrary web scripts in pages that execute if they can successf…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-39302 – BigBlueButton is an open-source virtual classroom designed to help teachers teac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39302</guid>
    <pubDate>Fri, 28 Jun 2024 21:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-39302</strong></p>
  <p>BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the `/usr/local/bigbluebutton/core/vendor/bundle/ruby/2.7.0/gems/resque-2.6.0` directory with the goal of privilege escalation, potentially exposing sensitive information on the server. This issue has been patched in versi…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-38518 – BigBlueButton is an open-source virtual classroom designed to help teachers teac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38518</guid>
    <pubDate>Fri, 28 Jun 2024 21:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-38518</strong></p>
  <p>BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. One of those parameters may be "role=moderator", allowing an attacker to join a meeting as moderator using a join link that was originally created for viewer acce…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-38273 – Insufficient capability checks meant it was possible for users to gain access to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38273</guid>
    <pubDate>Tue, 18 Jun 2024 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-38273</strong></p>
  <p>Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36029 – Greenlight is an end-user interface for BigBlueButton servers. Versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36029</guid>
    <pubDate>Thu, 25 Apr 2024 21:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36029</strong></p>
  <p>Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36028 – Greenlight is an end-user interface for BigBlueButton servers. Versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36028</guid>
    <pubDate>Thu, 25 Apr 2024 21:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36028</strong></p>
  <p>Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-5543 – When duplicating a BigBlueButton activity, the original meeting ID was also dupl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5543</guid>
    <pubDate>Thu, 09 Nov 2023 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-5543</strong></p>
  <p>When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-47107 – PILOS is an open source front-end for BigBlueButton servers with a built-in load...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47107</guid>
    <pubDate>Wed, 08 Nov 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-47107</strong></p>
  <p>PILOS is an open source front-end for BigBlueButton servers with a built-in load balancer. The password reset component deployed within PILOS uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to PILOS users when so that it points to the attackers server thereby disclosing the password reset token if/when the…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-43798 – BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43798</guid>
    <pubDate>Mon, 30 Oct 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-43798</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions 2.6.12 and 2.7.0-rc.1 disabled follow redirect at `httpclient.execute` since the software no longer has to follow it when using `finalUrl`. There are no known workarounds. We reco…</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-43797 – BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43797</guid>
    <pubDate>Mon, 30 Oct 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-43797</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe innerHTML. Text sanitizing was added for lobby messages starting in versions 2.6.11 and 2.7.0-beta.3. There are no known workarounds.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-42804 – BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42804</guid>
    <pubDate>Mon, 30 Oct 2023 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-42804</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vulnerability that allows an attacker with a valid starting folder path, to traverse and read other files without authentication, assuming the files have certain extensions (txt, swf, svg, png). In version 2.6.0-beta.1, input validation was added on the parameters being passed and d…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-42803 – BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42803</guid>
    <pubDate>Mon, 30 Oct 2023 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-42803</strong></p>
  <p>BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.2 is vulnerable to unrestricted file upload, where the insertDocument API call does not validate the given file extension before saving the file, and does not remove it in case of validation failures. BigBlueButton 2.6.0-beta.2 contains a patch. There are no known workarounds.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39991 – Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blindside Networks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39991</guid>
    <pubDate>Mon, 04 Sep 2023 11:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39991</strong></p>
  <p>Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blindside Networks BigBlueButton plugin <= 3.0.0-beta.4 versions.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-33176 – BigBlueButton is an open source virtual classroom designed to help teachers teac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33176</guid>
    <pubDate>Mon, 26 Jun 2023 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-33176</strong></p>
  <p>BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API request the user is able to supply a URL from which the presentation should be downloaded. This URL was being used without having been successfully validated first. An update to the…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23488 – BigBlueButton is an open source web conferencing system. Versions prior to 2.4-r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23488</guid>
    <pubDate>Sat, 17 Dec 2022 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23488</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are vulnerable to Insertion of Sensitive Information Into Sent Data. The moderators-only webcams lock setting is not enforced on the backend, which allows an attacker to subscribe to viewers' webcams, even when the lock setting is applied. (The required streamId was being sent to all users even with lock setting a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23490 – BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23490</guid>
    <pubDate>Fri, 16 Dec 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23490</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Versions prior to 2.4.0 expose sensitive information to Unauthorized Actors. This issue affects meetings with polls, where the attacker is a meeting participant. Subscribing to the current-poll collection does not update the client UI, but does give the attacker access to the contents of the collection, which include the individual poll res…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41964 – BigBlueButton is an open source web conferencing system. This vulnerability only...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41964</guid>
    <pubDate>Fri, 16 Dec 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41964</strong></p>
  <p>BigBlueButton is an open source web conferencing system. This vulnerability only affects release candidates of BigBlueButton 2.4. The attacker can start a subscription for poll results before starting an anonymous poll, and use this subscription to see individual responses in the anonymous poll. The attacker had to be a meeting presenter. This issue is patched in version 2.4.0. There are no worka…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2022-41963 – BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41963</guid>
    <pubDate>Fri, 16 Dec 2022 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2022-41963</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period could be used by attackers to take actions in the few seconds after their access is revoked. The attacker must be a meeting participant. This issue is patched in version 2.4.3 an version 2.5-alpha-1</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2022-41962 – BigBlueButton is an open source web conferencing system. Versions prior to 2.4-r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41962</guid>
    <pubDate>Fri, 16 Dec 2022 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2022-41962</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect Authorization for setting emoji status. A user with moderator rights can use the clear status feature to set any emoji status for other users. Moderators should only be able to set none as the status of other users. This issue is patched in 2.4-rc-6 and 2.5-alpha-1There are no wo…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41961 – BigBlueButton is an open source web conferencing system. Versions prior to 2.4-r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41961</guid>
    <pubDate>Fri, 16 Dec 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41961</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are subject to Ineffective user bans. The attacker could register multiple users, and join the meeting with one of them. When that user is banned, they could still join the meeting with the remaining registered users from the same extId. This issue has been fixed by improving permissions such that banning a user r…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41960 – BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41960</guid>
    <pubDate>Fri, 16 Dec 2022 00:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41960</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3, are subject to Insufficient Verification of Data Authenticity, resulting in Denial of Service. An attacker can make a Meteor call to `validateAuthToken` using a victim's userId, meetingId, and an invalid authToken. This forces the victim to leave the conference, because the resulting verification failure is also obs…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-27602 – BigBlueButton before 2.2.7 does not have a protection mechanism for separator in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27602</guid>
    <pubDate>Thu, 29 Sep 2022 03:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-27602</strong></p>
  <p>BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-27601 – In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not app...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27601</guid>
    <pubDate>Thu, 29 Sep 2022 03:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-27601</strong></p>
  <p>In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.js.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31065 – BigBlueButton is an open source web conferencing system. In affected versions an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31065</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31065</guid>
    <pubDate>Mon, 27 Jun 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31065</strong></p>
  <p>BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in their username and have it executed on the victim's client. When a user receives a private chat from the attacker (whose username contains malicious JavaScript), the script gets executed. Additionally when the victim receives a notification that the attacker has left the session. Th…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31065">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31064 – BigBlueButton is an open source web conferencing system. Users in meetings with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31064</guid>
    <pubDate>Mon, 27 Jun 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31064</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a cross site scripting attack in affected versions. The attack occurs when the attacker (with xss in the name) starts a chat. in the victim's client the JavaScript will be executed. This issue has been addressed in version 2.4.8 and 2.5.0. There are no known workarounds for this…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31039 – Greenlight is a simple front-end interface for your BigBlueButton server. In aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31039</guid>
    <pubDate>Mon, 27 Jun 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31039</strong></p>
  <p>Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has been patched in release version 2.12.6.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-27238 – BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27238</guid>
    <pubDate>Fri, 24 Jun 2022 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-27238</strong></p>
  <p>BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could inject JavaScript payload in his/her username. The payload gets executed in the browser of the victim each time the attacker sends a private message to the victim or when notification about the attacker leaving room is displayed.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-26497 – BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26497</guid>
    <pubDate>Thu, 02 Jun 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-26497</strong></p>
  <p>BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-29236 – BigBlueButton is an open source web conferencing system. Starting in version 2.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29236</guid>
    <pubDate>Thu, 02 Jun 2022 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-29236</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker can circumvent access restrictions for drawing on the whiteboard. The permission check is inadvertently skipped on the server, due to a previously introduced grace period. The attacker must be a meeting participant. The problem has been patched in versions 2.3.18…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-29235 – BigBlueButton is an open source web conferencing system. Starting in version 2.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29235</guid>
    <pubDate>Thu, 02 Jun 2022 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-29235</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc-6, an attacker who is able to obtain the meeting identifier for a meeting on a server can find information related to an external video being shared, like the current timestamp and play/pause. The problem has been patched in versions 2.3.18 and 2.4-rc-6 by modifying the stream…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-29234 – BigBlueButton is an open source web conferencing system. Starting in version 2.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29234</guid>
    <pubDate>Thu, 02 Jun 2022 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-29234</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1, an attacker could send messages to a locked chat within a grace period of 5s any lock setting in the meeting was changed. The attacker needs to be a participant in the meeting. Versions 2.3.18 and 2.4.1 contain a patch for this issue. There are currently no known workarounds.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-29233 – BigBlueButton is an open source web conferencing system. In BigBlueButton starti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29233</guid>
    <pubDate>Thu, 02 Jun 2022 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-29233</strong></p>
  <p>BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc-1, an attacker can circumvent access controls to gain access to all breakout rooms of the meeting they are in. The permission checks rely on knowledge of internal ids rather than on verification of the role of the user. Versions 2.3.18 and 2.4-rc-1 contain a patch for this issu…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-29232 – BigBlueButton is an open source web conferencing system. Starting with version 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29232</guid>
    <pubDate>Wed, 01 Jun 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-29232</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-beta-1, an attacker can circumvent access controls to obtain the content of public chat messages from different meetings on the server. The attacker must be a participant in a meeting on the server. BigBlueButton versions 2.3.9 and 2.4-beta-1 contain a patch for this issue. There…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29169 – BigBlueButton is an open source web conferencing system. Versions starting with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29169</guid>
    <pubDate>Wed, 01 Jun 2022 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29169</strong></p>
  <p>BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a RegularExpression, an attacker can cause denial of service for the bbb-html5 service. The useragent library performs checking of device by parsing the input of User-Agent header…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-4143 – Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigblueb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4143</guid>
    <pubDate>Wed, 19 Jan 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-4143</strong></p>
  <p>Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-29043 – An issue was discovered in BigBlueButton through 2.2.29. When at attacker is abl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29043</guid>
    <pubDate>Thu, 26 Nov 2020 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-29043</strong></p>
  <p>An issue was discovered in BigBlueButton through 2.2.29. When at attacker is able to view an account_activations/edit?token= URI, the attacker can create an approved user account associated with an email address that has an arbitrary domain name.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-29042 – An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29042</guid>
    <pubDate>Thu, 26 Nov 2020 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-29042</strong></p>
  <p>An issue was discovered in BigBlueButton through 2.2.29. A brute-force attack may occur because an unlimited number of codes can be entered for a meeting that is protected by an access code.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-28954 – web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28954</guid>
    <pubDate>Thu, 19 Nov 2020 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-28954</strong></p>
  <p>web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-28953 – In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28953</guid>
    <pubDate>Thu, 19 Nov 2020 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-28953</strong></p>
  <p>In BigBlueButton before 2.2.29, a user can vote more than once in a single poll.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-27642 – A cross-site scripting (XSS) vulnerability exists in the 'merge account' functio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27642</guid>
    <pubDate>Thu, 22 Oct 2020 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-27642</strong></p>
  <p>A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27613 – The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses Clue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27613</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27613</strong></p>
  <p>The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-27612 – Greenlight in BigBlueButton through 2.2.28 places usernames in room URLs, which ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27612</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-27612</strong></p>
  <p>Greenlight in BigBlueButton through 2.2.28 places usernames in room URLs, which may represent an unintended information leak to users in a room, or an information leak to outsiders if any user publishes a screenshot of a browser window.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27611 – BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27611</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27611</strong></p>
  <p>BigBlueButton through 2.2.28 uses STUN/TURN resources from a third party, which may represent an unintended endpoint.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27610 – The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27610</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27610</strong></p>
  <p>The installation procedure in BigBlueButton before 2.2.28 (or earlier) exposes certain network services to external interfaces, and does not automatically set up a firewall configuration to block external access.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-27609 – BigBlueButton through 2.2.28 records a video meeting despite the deactivation of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27609</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-27609</strong></p>
  <p>BigBlueButton through 2.2.28 records a video meeting despite the deactivation of video recording in the user interface. This may result in data storage beyond what is authorized for a specific meeting topic or participant.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-27608 – In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27608</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-27608</strong></p>
  <p>In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-27607 – In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only si...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27607</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-27607</strong></p>
  <p>In BigBlueButton before 2.2.28 (or earlier), the client-side Mute button only signifies that the server should stop accepting audio data from the client. It does not directly configure the client to stop sending audio data to the server, and thus a modified server could store the audio data and/or transmit it to one or more meeting participants or other third parties.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-27606 – BigBlueButton before 2.2.28 (or earlier) does not set the secure flag for the se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27606</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-27606</strong></p>
  <p>BigBlueButton before 2.2.28 (or earlier) does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-27605 – BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS doc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27605</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-27605</strong></p>
  <p>BigBlueButton through 2.2.28 uses Ghostscript for processing of uploaded EPS documents, and consequently may be subject to attacks related to a "schwache Sandbox."</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-27604 – BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27604</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-27604</strong></p>
  <p>BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared secret in the bigbluebutton.properties file. With the API shared secret, an attacker can (for example) use api/join to join an arbitrary meeting regardless of its guestPolicy setting.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-27603 – BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27603</guid>
    <pubDate>Wed, 21 Oct 2020 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-27603</strong></p>
  <p>BigBlueButton before 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-25820 – BigBlueButton before 2.2.7 allows remote authenticated users to read local files...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25820</guid>
    <pubDate>Wed, 21 Oct 2020 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-25820</strong></p>
  <p>BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploaded Office document that has a crafted URL in an ODF xlink field.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-26163 – BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26163</guid>
    <pubDate>Wed, 30 Sep 2020 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-26163</strong></p>
  <p>BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-12443 – BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files becau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12443</guid>
    <pubDate>Wed, 29 Apr 2020 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-12443</strong></p>
  <p>BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence. This can be leveraged for privilege escalation via a directory traversal to bigbluebutton.properties. NOTE: this issue exists because of an ineffective mitigation to CVE-2020-12112 in which there…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-12113 – BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12113</guid>
    <pubDate>Thu, 23 Apr 2020 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-12113</strong></p>
  <p>BigBlueButton before 2.2.4 allows XSS via closed captions because dangerouslySetInnerHTML in React is used.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12112 – BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12112</guid>
    <pubDate>Thu, 23 Apr 2020 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12112</strong></p>
  <p>BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12112">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
