TrueConf / Trueconf Server
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-72530 KEV | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlie… | CRITICAL | 9.5 | Aug 19, 2026 |
| CVE-2026-72529 KEV | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlie… | CRITICAL | 9.3 | Aug 19, 2026 |
| CVE-2025-66834 | A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via… | HIGH | 7.3 | Dec 30, 2025 |
| CVE-2025-66824 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10… | HIGH | 8.7 | Dec 30, 2025 |
| CVE-2025-66823 | An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Ed… | MEDIUM | 5.4 | Dec 30, 2025 |
| CVE-2022-46764 | A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL com… | CRITICAL | 9.8 | Dec 27, 2022 |
| CVE-2022-46763 | A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbi… | HIGH | 8.8 | Dec 27, 2022 |
| CVE-2017-20120 | TrueConf Server cross-site request forgery | HIGH | 8.8 | Jun 29, 2022 |
Showing 1 to 6 of 6 CVEs