Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

bigbluebutton — Vulnerabilities & Security Advisories 42

Browse all 42 CVE security advisories affecting bigbluebutton. AI-powered Chinese analysis, POCs, and references for each vulnerability.

BigBlueButton is an open-source virtual classroom platform designed for real-time online education, enabling video conferencing, screen sharing, and collaborative whiteboarding. Its architecture, primarily built on Node.js and React, has historically exposed it to a significant number of security flaws, currently totaling 34 recorded Common Vulnerabilities and Exposures. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Server-Side Request Forgery (SSRF), often stemming from inadequate input validation in its web interface and underlying services. Notable incidents involve critical RCE flaws that allowed attackers to execute arbitrary commands on the host system, compromising entire learning environments. While recent updates have addressed many of these issues, the complexity of its integration with external services like Redis and Nginx continues to present attack surfaces. Administrators must prioritize regular patching and strict access controls to mitigate these persistent risks in educational deployments.

CVE ID Title CVSS Severity Published
CVE-2022-41961 BigBlueButton subject to Ineffective user bans — bigbluebutton CWE-346 4.3 Medium 2022-12-16
CVE-2022-41960 BigBlueButton contains DoS via failed authToken validation — bigbluebutton CWE-345 4.3 Medium 2022-12-15
CVE-2022-31064 Cross site scripting in username that will trigger by sending chat — bigbluebutton CWE-79 6.5 Medium 2022-06-27
CVE-2022-31065 Cross site scripting vulnerability for private chat in bigbluebutton — bigbluebutton CWE-79 6.5 Medium 2022-06-27
CVE-2022-31039 Improper privilege management - Anyone can view room settings in GreenLight — greenlight CWE-269 4.3 Medium 2022-06-27
CVE-2022-29235 Limited data exposure for shared external videos in BigBlueButton — bigbluebutton CWE-200 5.3 Medium 2022-06-01
CVE-2022-29236 Improper access control for pencil annotations in BigBlueButton — bigbluebutton CWE-285 4.3 Medium 2022-06-01
CVE-2022-29234 Grace period for lock settings in public/private chats in BigBlueButton — bigbluebutton CWE-285 4.3 Medium 2022-06-01
CVE-2022-29233 Improper access control for breakout rooms in BigBlue Button — bigbluebutton CWE-285 4.3 Medium 2022-06-01
CVE-2022-29232 Exposure of messages in BigBlueButton public chats — bigbluebutton CWE-200 6.5 Medium 2022-06-01
CVE-2022-29169 ReDoS on endpoint html5client/useragent in BigBlueButton — bigbluebutton CWE-20 7.5 High 2022-06-01
CVE-2021-4143 Cross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebutton — bigbluebutton/bigbluebutton CWE-79 6.1 - 2022-01-19

This page lists every published CVE security advisory associated with bigbluebutton. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.