Openmeetings
by Apache
Source repositories
CVEs (29)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-1286 | Med | 0.42 | 6.5 | 0.01 | Feb 28, 2018 | In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users. | ||
| CVE-2023-29246 | Hig | 0.40 | 7.2 | 0.01 | May 12, 2023 | An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0 | ||
| CVE-2017-7663 | Med | 0.40 | 6.1 | 0.03 | Jul 17, 2017 | Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0. | ||
| CVE-2016-2163 | Med | 0.40 | 6.1 | 0.08 | Apr 11, 2016 | Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event. | ||
| CVE-2017-7685 | Med | 0.35 | 5.3 | 0.03 | Jul 17, 2017 | Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH. | ||
| CVE-2016-3089 | Med | 0.33 | 6.1 | 0.05 | Aug 19, 2016 | Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the swf parameter. | ||
| CVE-2023-28936 | Med | 0.28 | 5.3 | 0.01 | May 12, 2023 | Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0 | ||
| CVE-2026-33005 | Med | 0.21 | 4.3 | 0.00 | Apr 9, 2026 | Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field.… | ||
| CVE-2026-49488 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS… |
- risk 0.42cvss 6.5epss 0.01
In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users.
- risk 0.40cvss 7.2epss 0.01
An attacker who has gained access to an admin account can perform RCE via null-byte injection Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
- risk 0.40cvss 6.1epss 0.03
Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.
- risk 0.40cvss 6.1epss 0.08
Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event.
- risk 0.35cvss 5.3epss 0.03
Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.
- risk 0.33cvss 6.1epss 0.05
Cross-site scripting (XSS) vulnerability in the SWF panel in Apache OpenMeetings before 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the swf parameter.
- risk 0.28cvss 5.3epss 0.01
Attacker can access arbitrary recording/room Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.1.0
- risk 0.21cvss 4.3epss 0.00
Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field.…
- risk 0.00cvss 6.5epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An attacker with moderator rights in any room can read arbitrary files accessible to the OS…
Page 2 of 2