Bigbluebutton / Greenlight
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-36029 | BigBlueButton Greenlight Open Redirect vulnerability | CRITICAL | 9.1 | Apr 25, 2024 |
| CVE-2022-36028 | BigBlueButton Greenlight Open Redirect vulnerability | CRITICAL | 9.1 | Apr 25, 2024 |
| CVE-2022-31039 | Improper privilege management - Anyone can view room settings in GreenLight | MEDIUM | 5.3 | Jun 27, 2022 |
| CVE-2022-26497 | BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of t… | MEDIUM | 5.4 | Jun 2, 2022 |
| CVE-2020-27642 | A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6. | MEDIUM | 6.1 | Oct 22, 2020 |
| CVE-2020-26163 | BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password… | HIGH | 8.8 | Sep 30, 2020 |
Showing 1 to 6 of 6 CVEs