Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache OpenMeetings — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in Apache OpenMeetings, with AI-generated Chinese analysis, references, and POCs.

This page documents security weaknesses associated with Apache OpenMeetings, specifically focusing on vulnerability aggregations within the software ecosystem. It compiles a comprehensive list of identified security flaws, ranging from cross-site scripting and injection attacks to improper access control issues, covering incidents reported from early development stages through recent stable releases. By visiting this resource, users can efficiently track official advisories released by the Apache Software Foundation, gain a deeper understanding of specific weakness classifications such as CWE-79 or CWE-862, and review the complete historical timeline of vulnerabilities affecting this collaborative conferencing software. This structured approach allows administrators, developers, and security analysts to assess the risk posture of their deployments without sifting through unorganized data. The information presented is strictly factual, designed to support informed decision-making regarding patch management and system hardening. It serves as a centralized reference point for anyone responsible for maintaining the integrity and confidentiality of Apache OpenMeetings installations. Readers will find clear mappings between reported issues and their underlying technical causes, facilitating faster remediation efforts. This documentation does not speculate on future threats but rather relies on verified historical data to provide context and clarity. For organizations relying on this platform for real-time collaboration, maintaining awareness of these past incidents is crucial for preventing recurrence and ensuring a robust security hygiene. The page is updated regularly to reflect new disclosures and ensures that all relevant details are accessible in one consolidated location for ease of reference and analysis.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2026-49488 Apache OpenMeetings: Arbitrary File Read CWE-22--2026-07-14
CVE-2026-33005 Apache OpenMeetings: Insufficient checks in FileWebService CWE-274 4.3AIMediumAI2026-04-09
CVE-2026-33266 Apache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and Salt CWE-321 9.8AICriticalAI2026-04-09
CVE-2026-34020 Apache OpenMeetings: Login Credentials Passed via GET Query Parameters CWE-598 7.5AIHighAI2026-04-09
CVE-2024-54676 Apache OpenMeetings: Deserialisation of untrusted data in cluster mode CWE-502 9.8 -2025-01-08
CVE-2023-28936 Apache OpenMeetings: insufficient check of invitation hash CWE-697 7.5 -2023-05-12
CVE-2023-29032 Apache OpenMeetings: allows bypass authentication CWE-287 8.8 -2023-05-12
CVE-2023-29246 Apache OpenMeetings: allows null-byte Injection CWE-20 7.2 -2023-05-12
CVE-2023-28326 Apache OpenMeetings: allows user impersonation CWE-306 9.8 -2023-03-28
CVE-2021-27576 Apache OpenMeetings: bandwidth can be overloaded with public web service 7.5 -2021-03-15
CVE-2020-13951 Apache OpenMeetings 安全漏洞 7.5 -2020-09-30
CVE-2018-1286 Apache OpenMeetings 安全漏洞 6.5 -2018-02-28
CVE-2016-8736 Apache OpenMeetings 安全漏洞 9.8 -2017-10-12
CVE-2017-7688 Apache OpenMeetings 安全漏洞 7.5 -2017-07-14
CVE-2017-7685 Apache OpenMeetings 访问控制错误漏洞 7.5 -2017-07-14
CVE-2017-7684 Apache OpenMeetings 安全漏洞 7.5 -2017-07-14
CVE-2017-7683 Apache OpenMeetings 信息泄露漏洞 7.5 -2017-07-14
CVE-2017-7682 Apache OpenMeetings 安全漏洞 8.2 -2017-07-14
CVE-2017-7681 Apache OpenMeetings SQL注入漏洞 8.1 -2017-07-14
CVE-2017-7680 Apache OpenMeetings 安全漏洞 7.5 -2017-07-14
CVE-2017-7673 Apache OpenMeetings 安全漏洞 9.8 -2017-07-14
CVE-2017-7666 Apache OpenMeetings 跨站请求伪造漏洞 8.8 -2017-07-14
CVE-2017-7664 Apache OpenMeetings 安全漏洞 9.4 -2017-07-14
CVE-2017-7663 Apache OpenMeetings 跨站脚本漏洞 6.1 -2017-07-14

All 24 known CVE vulnerabilities affecting Apache OpenMeetings with full Chinese analysis, references, and POCs where available.