Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Apache OpenMeetings — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in Apache OpenMeetings, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities classified as Common Weakness Enumeration flaws for the Apache OpenMeetings product developed by The Apache Software Foundation. It aggregates a comprehensive list of reported security issues, including remote code execution, cross-site scripting, and information disclosure weaknesses that have affected this collaborative web conferencing system. The dataset covers known vulnerabilities from the product's initial public releases through recent updates, ensuring a broad historical perspective on its security posture. Readers can use this resource to track advisory releases from the vendor, gaining insight into how quickly patches are deployed for critical threats. Additionally, the page serves as a reference for understanding the specific weak categories prevalent in this software, such as improper input validation or authentication bypasses. Users can look up the complete vulnerability history for Apache OpenMeetings to assess risk exposure over time and identify recurring patterns in defect types. This aggregated view helps security professionals and administrators evaluate the maturity of the product's security practices. By reviewing these entries, stakeholders can better prioritize updates and understand the context of past security incidents. The information is presented to facilitate informed decision-making regarding system maintenance and risk mitigation strategies without relying on speculative data.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2026-33005 Apache OpenMeetings: Insufficient checks in FileWebService CWE-274 4.3AIMediumAI2026-04-09
CVE-2026-33266 Apache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and Salt CWE-321 9.8AICriticalAI2026-04-09
CVE-2026-34020 Apache OpenMeetings: Login Credentials Passed via GET Query Parameters CWE-598 7.5AIHighAI2026-04-09
CVE-2024-54676 Apache OpenMeetings: Deserialisation of untrusted data in cluster mode CWE-502 9.8 -2025-01-08
CVE-2023-28936 Apache OpenMeetings: insufficient check of invitation hash CWE-697 7.5 -2023-05-12
CVE-2023-29032 Apache OpenMeetings: allows bypass authentication CWE-287 8.8 -2023-05-12
CVE-2023-29246 Apache OpenMeetings: allows null-byte Injection CWE-20 7.2 -2023-05-12
CVE-2023-28326 Apache OpenMeetings: allows user impersonation CWE-306 9.8 -2023-03-28
CVE-2021-27576 Apache OpenMeetings: bandwidth can be overloaded with public web service 7.5 -2021-03-15
CVE-2020-13951 Apache OpenMeetings 安全漏洞 7.5 -2020-09-30
CVE-2018-1286 Apache OpenMeetings 安全漏洞 6.5 -2018-02-28
CVE-2016-8736 Apache OpenMeetings 安全漏洞 9.8 -2017-10-12
CVE-2017-7688 Apache OpenMeetings 安全漏洞 7.5 -2017-07-14
CVE-2017-7685 Apache OpenMeetings 访问控制错误漏洞 7.5 -2017-07-14
CVE-2017-7684 Apache OpenMeetings 安全漏洞 7.5 -2017-07-14
CVE-2017-7683 Apache OpenMeetings 信息泄露漏洞 7.5 -2017-07-14
CVE-2017-7682 Apache OpenMeetings 安全漏洞 8.2 -2017-07-14
CVE-2017-7681 Apache OpenMeetings SQL注入漏洞 8.1 -2017-07-14
CVE-2017-7680 Apache OpenMeetings 安全漏洞 7.5 -2017-07-14
CVE-2017-7673 Apache OpenMeetings 安全漏洞 9.8 -2017-07-14
CVE-2017-7666 Apache OpenMeetings 跨站请求伪造漏洞 8.8 -2017-07-14
CVE-2017-7664 Apache OpenMeetings 安全漏洞 9.4 -2017-07-14
CVE-2017-7663 Apache OpenMeetings 跨站脚本漏洞 6.1 -2017-07-14

All 23 known CVE vulnerabilities affecting Apache OpenMeetings with full Chinese analysis, references, and POCs where available.