VendorsTrueConftrueconf_serverall versions
Vulnerabilities

TrueConf Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-72529
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Published 2026-08-19 · Analyzed
9.8KEVEPSS 0.015
CVE-2026-72530
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Published 2026-08-19 · Analyzed
9.5KEVEPSS 0.017
CVE-2017-20120
TrueConf Server cross-site request forgery
Published 2022-06-29 · Modified
8.8EPSS 0.005
CVE-2025-66824
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is caused by improper sanitization of user-supplied input in the meeting_room field.
Published 2025-12-30 · Analyzed
8.7EPSS 0.003
CVE-2025-66834
A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadsheet formulas into exported chat logs via crafted Display Name.
Published 2025-12-30 · Analyzed
7.3EPSS 0.003
CVE-2025-66823
An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Conference Info page ([conference url]/info).
Published 2025-12-30 · Analyzed
5.4EPSS 0.002