Apache / Openmeetings
29 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-49488 | Apache OpenMeetings: Arbitrary File Read | MEDIUM | 6.5 | Jul 14, 2026 |
| CVE-2026-33005 | Apache OpenMeetings: Insufficient checks in FileWebService | MEDIUM | 5.3 | Apr 9, 2026 |
| CVE-2026-33266 | Apache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and Salt | HIGH | 8.7 | Apr 9, 2026 |
| CVE-2026-34020 | Apache OpenMeetings: Login Credentials Passed via GET Query Parameters | HIGH | 8.7 | Apr 9, 2026 |
| CVE-2024-54676 | Apache OpenMeetings: Deserialisation of untrusted data in cluster mode | CRITICAL | 9.3 | Jan 8, 2025 |
| CVE-2023-28936 | Apache OpenMeetings: insufficient check of invitation hash | MEDIUM | 5.3 | May 12, 2023 |
| CVE-2023-29032 | Apache OpenMeetings: allows bypass authentication | HIGH | 8.1 | May 12, 2023 |
| CVE-2023-29246 | Apache OpenMeetings: allows null-byte Injection | HIGH | 7.2 | May 12, 2023 |
| CVE-2023-28326 | Apache OpenMeetings: allows user impersonation | CRITICAL | 9.8 | Mar 28, 2023 |
| CVE-2021-27576 | Apache OpenMeetings: bandwidth can be overloaded with public web service | HIGH | 7.5 | Mar 15, 2021 |
| CVE-2020-13951 | Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack. | HIGH | 7.5 | Sep 30, 2020 |
| CVE-2018-1286 | In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for pri… | MEDIUM | 6.5 | Feb 28, 2018 |
| CVE-2016-8736 | Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack. | CRITICAL | 9.8 | Oct 12, 2017 |
| CVE-2017-7688 | Apache OpenMeetings 1.0.0 updates user password in insecure manner. | HIGH | 7.5 | Jul 14, 2017 |
| CVE-2017-7685 | Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH. | MEDIUM | 5.3 | Jul 14, 2017 |
| CVE-2017-7684 | Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files to the se… | HIGH | 7.5 | Jul 14, 2017 |
| CVE-2017-7683 | Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure. | HIGH | 7.5 | Jul 14, 2017 |
| CVE-2017-7682 | Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas. | HIGH | 8.2 | Jul 14, 2017 |
| CVE-2017-7681 | Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure… | HIGH | 8.8 | Jul 14, 2017 |
| CVE-2017-7680 | Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains. | HIGH | 7.5 | Jul 14, 2017 |
| CVE-2017-7673 | Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing br… | CRITICAL | 9.8 | Jul 14, 2017 |
| CVE-2017-7666 | Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks. | HIGH | 8.8 | Jul 14, 2017 |
| CVE-2017-7664 | Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0. | CRITICAL | 10.0 | Jul 14, 2017 |
| CVE-2017-7663 | Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0. | MEDIUM | 6.1 | Jul 14, 2017 |
| CVE-2016-3089 | Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script or HTML vi… | MEDIUM | 6.1 | Aug 19, 2016 |
Showing 1 to 25 of 29 CVEs