VendorsBigBlueButtongreenlightall versions
Vulnerabilities

BigBlueButton Greenlight

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-36029
BigBlueButton Greenlight Open Redirect vulnerability
Published 2024-04-25 · Analyzed
9.1EPSS 0.004
CVE-2022-36028
BigBlueButton Greenlight Open Redirect vulnerability
Published 2024-04-25 · Analyzed
9.1EPSS 0.004
CVE-2020-26163
BigBlueButton Greenlight before 2.5.6 allows HTTP header (Host and Origin) attacks, which can result in Account Takeover if a victim follows a spoofed password-reset link.
Published 2020-09-30 · Modified
8.8EPSS 0.015
CVE-2020-27642
A cross-site scripting (XSS) vulnerability exists in the 'merge account' functionality in admins.js in BigBlueButton Greenlight 2.7.6.
Published 2020-10-22 · Modified
6.1EPSS 0.008
CVE-2022-26497
BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.
Published 2022-06-02 · Modified
5.4EPSS 0.008
CVE-2022-31039
Improper privilege management - Anyone can view room settings in GreenLight
Published 2022-06-27 · Modified
5.3EPSS 0.007