VendorsPexippexip_infinityall versions
Vulnerabilities

Pexip Pexip Infinity

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

47CVEs
CVE-2017-17477
Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.
Published 2020-09-25 · Modified
6.1EPSS 0.008
CVE-2023-37225
Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links.
Published 2023-12-25 · Modified
6.1EPSS 0.003
CVE-2022-27930
Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Universally Unique Identifier is guessed.
Published 2022-07-17 · Modified
5.9EPSS 0.009
CVE-2025-49088
Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial of service.
Published 2025-12-25 · Analyzed
5.9EPSS 0.003
CVE-2020-24615
Pexip Infinity before 24.1 has Improper Input Validation, leading to temporary denial of service via SIP.
Published 2020-09-25 · Modified
5.3EPSS 0.010
CVE-2022-25357
Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if it has a lock but not a PIN.
Published 2022-07-17 · Modified
5.3EPSS 0.006
CVE-2024-33850
Pexip Infinity before 34.1 has Improper Access Control for persons in a waiting room. They can see the conference roster list, and perform certain actions that should not be allowed before they are admitted to the meeting.
Published 2024-06-10 · Analyzed
4.3EPSS 0.002
← Prev2 / 2