VYPR

Server

by Trueconf

CVEs (5)

  • CVE-2025-66824HigDec 30, 2025
    risk 0.57cvss 8.7epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info…

  • CVE-2025-66823MedDec 30, 2025
    risk 0.35cvss 5.4epss 0.00

    An HTML Injection vulnerability in TrueConf server 5.5.2.10813 in the conference description field allows an attacker to inject arbitrary HTML in the Create/Edit conference functionality. The payload will be triggered when the victim opens the Conference Info page ([conference…

  • CVE-2017-20118LowJun 29, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in TrueConf Server 4.3.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/conferences/list/. The manipulation of the argument domxss leads to basic cross site scripting (DOM). The attack may be…

  • CVE-2017-20116LowJun 29, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in TrueConf Server 4.3.7. It has been classified as problematic. Affected is an unknown function of the file /admin/group/list/. The manipulation of the argument checked_group_id leads to basic cross site scripting (Reflected). It is possible to launch…

  • CVE-2017-20114LowJun 29, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability has been found in TrueConf Server 4.3.7 and classified as problematic. This vulnerability affects unknown code of the file /admin/conferences/get-all-status/. The manipulation of the argument keys[] leads to basic cross site scripting (Reflected). The attack can…