Bigbluebutton
41 CVEs tracked since 2020. Since Oct 2020, none of them reached CISA KEV.
Bigbluebutton CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-10 | 15 | 0 |
| 2020-11 | 4 | 0 |
| 2020-12 | null or fewer | |
| 2021-01 | null or fewer | |
| 2021-02 | null or fewer | |
| 2021-03 | null or fewer | |
| 2021-04 | null or fewer | |
| 2021-05 | null or fewer | |
| 2021-06 | null or fewer | |
| 2021-07 | null or fewer | |
| 2021-08 | null or fewer | |
| 2021-09 | null or fewer | |
| 2021-10 | null or fewer | |
| 2021-11 | null or fewer | |
| 2021-12 | null or fewer | |
| 2022-01 | null or fewer | |
| 2022-02 | null or fewer | |
| 2022-03 | null or fewer | |
| 2022-04 | null or fewer | |
| 2022-05 | null or fewer | |
| 2022-06 | 11 | 0 |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | 7 | 0 |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | 4 | 0 |
Products
The products that kept showing up in Bigbluebutton's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Bigbluebutton.
- CVE-2026-55489BigBlueButton: IDOR on BBB through /api/graphql via POST parameter "presentationId" leads to Authentication Bypass4.9
- CVE-2026-55491BigBlueButton: Stored XSS in Screenshare Recording Playback via Unescaped Meeting Name5.4
- CVE-2026-46355BigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUser7.1
- CVE-2026-46682BigBlueButton: Blind SQL Injection AUTH (Moderator)8.5
- CVE-2026-46353BigBlueButton API checksum bypass via presentationUploadExternalUrl8.1
- CVE-2026-46404BigBlueButton: Presentation URL Security Hardening6.8
- CVE-2026-46351BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate them8.1
- CVE-2026-27737BigBlueButton has Stored XSS in bbb-playback replay6.5
- CVE-2026-41127BigBlueButton's missing authorization allows viewer to inject/overwrite captions6.5
- CVE-2026-41126BigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL"4.3
- CVE-2026-27736BigBlueButton has Open Redirect vulnerability in ApiController6.1
- CVE-2026-27467BigBlueButton: Audio from participants to the server initially unmuted2.0
- CVE-2026-27466BigBlueButton: Exposed ClamAV port enables Denial of Service7.2
- CVE-2025-61602BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId7.5
- CVE-2025-61601BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation7.5
The record
- Peak rank
- #34 in Oct 2020
- Busiest month shown
- Oct 2020, 15 CVEs
- Months with a KEV entry
- 0 since Oct 2020
- Monthly snapshots
- 5 since 2020