VYPR

Openmeetings

by Apache

Source repositories

CVEs (29)

  • CVE-2018-1286MedFeb 28, 2018
    risk 0.42cvss 6.5epss 0.01

    In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.

  • CVE-2023-29246HigMay 12, 2023
    risk 0.40cvss 7.2epss 0.01

    An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0

  • CVE-2017-7663MedJul 17, 2017
    risk 0.40cvss 6.1epss 0.03

    Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.

  • CVE-2016-2163MedApr 11, 2016
    risk 0.40cvss 6.1epss 0.08

    Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event.

  • CVE-2017-7685MedJul 17, 2017
    risk 0.35cvss 5.3epss 0.03

    Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.

  • CVE-2016-3089MedAug 19, 2016
    risk 0.33cvss 6.1epss 0.05

    Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the swf parameter.

  • CVE-2023-28936MedMay 12, 2023
    risk 0.28cvss 5.3epss 0.01

    Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0

  • CVE-2026-33005MedApr 9, 2026
    risk 0.21cvss 4.3epss 0.00

    Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field.…

  • CVE-2026-49488MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS…

Page 2 of 2