Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

bigbluebutton — Vulnerabilities & Security Advisories 42

Browse all 42 CVE security advisories affecting bigbluebutton. AI-powered Chinese analysis, POCs, and references for each vulnerability.

BigBlueButton is an open-source virtual classroom platform designed for real-time online education, enabling video conferencing, screen sharing, and collaborative whiteboarding. Its architecture, primarily built on Node.js and React, has historically exposed it to a significant number of security flaws, currently totaling 34 recorded Common Vulnerabilities and Exposures. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and Server-Side Request Forgery (SSRF), often stemming from inadequate input validation in its web interface and underlying services. Notable incidents involve critical RCE flaws that allowed attackers to execute arbitrary commands on the host system, compromising entire learning environments. While recent updates have addressed many of these issues, the complexity of its integration with external services like Redis and Nginx continues to present attack surfaces. Administrators must prioritize regular patching and strict access controls to mitigate these persistent risks in educational deployments.

Found 38 results / 42 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-55489 BigBlueButton: IDOR on BBB through /api/graphql via POST parameter "presentationId" leads to Authentication Bypass — bigbluebutton CWE-639 4.9 Medium 2026-08-20
CVE-2026-55491 BigBlueButton: Stored XSS in Screenshare Recording Playback via Unescaped Meeting Name — bigbluebutton CWE-79 5.4 Medium 2026-08-20
CVE-2026-46355 BigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUser — bigbluebutton CWE-287 7.1 High 2026-08-20
CVE-2026-46682 BigBlueButton: Blind SQL Injection AUTH (Moderator) — bigbluebutton CWE-89 8.5 High 2026-08-20
CVE-2026-46353 BigBlueButton API checksum bypass via presentationUploadExternalUrl — bigbluebutton CWE-284 8.1 High 2026-07-16
CVE-2026-46404 BigBlueButton: Presentation URL Security Hardening — bigbluebutton CWE-918 6.8 Medium 2026-07-16
CVE-2026-46351 BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate them — bigbluebutton CWE-330 8.1 High 2026-07-16
CVE-2026-27737 BigBlueButton has Stored XSS in bbb-playback replay — bigbluebutton CWE-79 6.5 Medium 2026-05-18
CVE-2026-41127 BigBlueButton's missing authorization allows viewer to inject/overwrite captions — bigbluebutton CWE-639 6.5 Medium 2026-04-21
CVE-2026-41126 BigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL" — bigbluebutton CWE-601 4.3 Medium 2026-04-21
CVE-2026-27736 BigBlueButton has Open Redirect vulnerability in ApiController — bigbluebutton CWE-601 6.1 Medium 2026-02-25
CVE-2026-27467 BigBlueButton: Audio from participants to the server initially unmuted — bigbluebutton CWE-200 2.0 Low 2026-02-21
CVE-2026-27466 BigBlueButton: Exposed ClamAV port enables Denial of Service — bigbluebutton CWE-668 7.2 High 2026-02-21
CVE-2025-61602 BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId — bigbluebutton CWE-703 7.5 High 2025-10-09
CVE-2025-61601 BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation — bigbluebutton CWE-703 7.5 High 2025-10-09
CVE-2025-55200 BigBlueButton vulnerable to Stored XSS via name of user at Shared Notes — bigbluebutton CWE-79 7.1 High 2025-10-09
CVE-2024-39302 Some bbb-record-core files installed with wrong file permission — bigbluebutton CWE-269 3.7 Low 2024-06-28
CVE-2024-38518 bbb-web API additional parameters considered — bigbluebutton CWE-284 4.6 Medium 2024-06-28
CVE-2023-43798 BigBlueButton Blind SSRF When Uploading Presentation (mitigation bypass) — bigbluebutton CWE-918 5.6 Medium 2023-10-30
CVE-2023-43797 BigBlueButton Stored Cross-site Scripting vulnerability at Guest Lobby — bigbluebutton CWE-79 6.3 Medium 2023-10-30
CVE-2023-42804 BigBlueButton Path Traversal – Reading Certain File Extensions — bigbluebutton CWE-22 3.1 Low 2023-10-30
CVE-2023-42803 BigBlueButton Unrestricted File Upload vulnerability — bigbluebutton CWE-434 5.3 Medium 2023-10-30
CVE-2023-33176 Blind SSRF When Uploading Presentation in BigBlueButton — bigbluebutton CWE-918 4.8 Medium 2023-06-26
CVE-2022-23488 BigBlueButton vulnerable to Insertion of Sensitive Information Into Sent Data — bigbluebutton CWE-201 6.5 Medium 2022-12-17
CVE-2022-23490 Improper access control to polling votes — bigbluebutton CWE-200 4.3 Medium 2022-12-16
CVE-2022-41964 BigBlueButton contains Response leaks in anonymous polls — bigbluebutton CWE-200 5.7 Medium 2022-12-16
CVE-2022-41963 BigBlueButton contains Improper Preservation of Permissions for whiteboard — bigbluebutton CWE-281 2.7 Low 2022-12-16
CVE-2022-41962 BigBlueButton contains Incorrect Authorization for setting emoji status — bigbluebutton CWE-863 2.7 Low 2022-12-16
CVE-2022-41961 BigBlueButton subject to Ineffective user bans — bigbluebutton CWE-346 4.3 Medium 2022-12-16
CVE-2022-41960 BigBlueButton contains DoS via failed authToken validation — bigbluebutton CWE-345 4.3 Medium 2022-12-15

This page lists every published CVE security advisory associated with bigbluebutton. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.