VendorsCiscowebex_meetingsall versions
Vulnerabilities

Cisco Webex Meetings

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

69CVEs
CVE-2025-20247
A vulnerability in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. A vulnerability is due to improper filtering of user-supplied input. An attacker could exploit this vulnerability by persuading a user to follow a malicious link. A successful exploit could allow the attacker to conduct a cross-site scripting attack against the targeted user.
Published 2025-05-21 · Analyzed
6.1EPSS 0.003
CVE-2025-20291
A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to redirect a targeted Webex Meetings user to an untrusted website. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed. This vulnerability existed because of insufficient validation of URLs that were included in a meeting-join URL. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by including a URL to a website of their choosing in a specific value of a Cisco Webex Meetings join URL. A successful exploit could have allowed the attacker to redirect a targeted user to a website that was controlled by the attacker, possibly making the user more likely to believe the website was trusted by Webex and perform additional actions as part of phishing attacks.
Published 2025-09-03 · Analyzed
6.1EPSS 0.002
CVE-2026-20233
Cisco Webex Meetings Cross-Site Scripting Vulnerability
Published 2026-06-03 · Analyzed
6.1EPSS 0.002
CVE-2019-1948
Cisco Webex Meetings Mobile (iOS) SSL Certificate Validation Vulnerability
Published 2019-08-21 · Modified
5.9EPSS 0.009
CVE-2021-1311
Cisco Webex Meetings and Cisco Webex Meetings Server Host Key Brute Forcing Vulnerability
Published 2021-01-13 · Modified
5.5EPSS 0.013
CVE-2021-1372
Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure Vulnerability
Published 2021-02-17 · Modified
5.5EPSS 0.004
CVE-2020-3347
Cisco Webex Meetings Desktop App for Windows Shared Memory Information Disclosure Vulnerability
Published 2020-06-18 · Modified
5.5EPSS 0.004
CVE-2021-1544
Cisco Webex Meetings Client Software Logging Information Disclosure Vulnerability
Published 2021-06-04 · Modified
5.5EPSS 0.002
CVE-2023-20133
A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because of insufficient validation of user-supplied input in Webex Events (classic) programs, email templates, and survey questions. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Published 2023-07-07 · Modified
5.4EPSS 0.006
CVE-2022-20820
Cisco Webex Meetings Web Interface Vulnerabilities
Published 2022-08-10 · Modified
5.4EPSS 0.005
CVE-2023-20132
Cisco Webex Meetings Web UI Vulnerabilities
Published 2023-04-05 · Modified
5.4EPSS 0.004
CVE-2025-20328
A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attacker with low privileges to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. Cisco has addressed this vulnerability in the Cisco Webex Meetings service, and no customer action is needed. This vulnerability existed because of insufficient validation of user-supplied input to the user profile component of Cisco Webex Meetings. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could have allowed the attacker to conduct an XSS attack against the targeted user.
Published 2025-09-03 · Analyzed
5.4EPSS 0.002
CVE-2020-3441
Cisco Webex Meetings and Cisco Webex Meetings Server Information Disclosure Vulnerability
Published 2020-11-18 · Modified
5.3EPSS 0.016
CVE-2021-40128
Cisco Webex Meetings Email Content Injection Vulnerability
Published 2021-11-04 · Modified
5.3EPSS 0.010
CVE-2019-16001
Cisco Webex Teams for Windows DLL Hijacking Vulnerability
Published 2019-11-26 · Modified
5.3EPSS 0.004
CVE-2019-1677
Cisco Webex Meetings for Android Cross-Site Scripting Vulnerability
Published 2019-02-07 · Modified
5.0EPSS 0.004
CVE-2021-1310
Cisco Webex Meetings Open Redirect Vulnerability
Published 2021-01-13 · Modified
4.7EPSS 0.016
CVE-2021-1420
Cisco Webex Meetings HTML Injection Vulnerability
Published 2021-04-08 · Modified
4.7EPSS 0.009
CVE-2020-3541
Cisco Webex Meetings Client for Windows, Webex Meetings Desktop App, and Webex Teams Information Disclosure Vulnerability
Published 2020-09-04 · Modified
4.4EPSS 0.003
CVE-2015-6384
The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom application permissions, which allows attackers to bypass intended access restrictions via a crafted application, aka Bug ID CSCuw86442.
Published 2015-12-05 · Modified
4.3EPSS 0.015
CVE-2020-3345
Cisco Webex Meetings and Cisco Webex Meetings Server HTML Injection Vulnerability
Published 2020-07-16 · Modified
4.3EPSS 0.012
CVE-2021-1410
Cisco Webex Meetings Unauthorized Distribution List Update Vulnerability
Published 2024-11-18 · Analyzed
4.3EPSS 0.008
CVE-2021-1467
Cisco Webex Meetings for Android Avatar Modification Vulnerability
Published 2021-04-08 · Modified
4.3EPSS 0.007
CVE-2020-3182
Cisco Webex Meetings Client for MacOS Information Disclosure Vulnerability
Published 2020-03-04 · Modified
4.3EPSS 0.005
CVE-2023-20180
A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web interface on an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions. These actions could include joining meetings and scheduling training sessions.
Published 2023-07-07 · Modified
4.3EPSS 0.004
CVE-2025-20255
A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses within the meeting join service. This vulnerability is due to improper handling of malicious HTTP requests to the affected service. An attacker could exploit this vulnerability by manipulating stored HTTP responses within the service, also known as HTTP cache poisoning. A successful exploit could allow the attacker to cause the Webex Meetings service to return incorrect HTTP responses to clients.
Published 2025-05-21 · Analyzed
4.3EPSS 0.002
CVE-2021-1221
Cisco Webex Meetings and Cisco Webex Meetings Server Software Hyperlink Injection Vulnerability
Published 2021-02-04 · Modified
4.1EPSS 0.010
CVE-2020-3502
Cisco Webex Meetings Desktop App Information Disclosure Vulnerabilities
Published 2020-08-17 · Modified
4.1EPSS 0.010
CVE-2020-3501
Cisco Webex Meetings Desktop App Information Disclosure Vulnerabilities
Published 2020-08-17 · Modified
4.1EPSS 0.010
← Prev2 / 2