CVE Tools

Bigbluebutton

41 CVEs tracked since 2020. Since Oct 2020, none of them reached CISA KEV.

Bigbluebutton CVEs per month

Oct 2020 to Oct 2023. Point at a month, or focus the strip and use the arrow keys.
Bigbluebutton CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-10150
2020-1140
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06110
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-1270
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-1040

Products

The products that kept showing up in Bigbluebutton's monthly top three, with their CVEs summed over those months.

  1. Bigbluebutton385 months
  2. Greenlight32 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Bigbluebutton.

  1. CVE-2026-55489BigBlueButton: IDOR on BBB through /api/graphql via POST parameter "presentationId" leads to Authentication Bypass4.9
  2. CVE-2026-55491BigBlueButton: Stored XSS in Screenshare Recording Playback via Unescaped Meeting Name5.4
  3. CVE-2026-46355BigBlueButton: Unauthenticated Session Hijack via Exposed /bigbluebutton/api/handleJoinExistingUser7.1
  4. CVE-2026-46682BigBlueButton: Blind SQL Injection AUTH (Moderator)8.5
  5. CVE-2026-46353BigBlueButton API checksum bypass via presentationUploadExternalUrl8.1
  6. CVE-2026-46404BigBlueButton: Presentation URL Security Hardening6.8
  7. CVE-2026-46351BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate them8.1
  8. CVE-2026-27737BigBlueButton has Stored XSS in bbb-playback replay6.5
  9. CVE-2026-41127BigBlueButton's missing authorization allows viewer to inject/overwrite captions6.5
  10. CVE-2026-41126BigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL"4.3
  11. CVE-2026-27736BigBlueButton has Open Redirect vulnerability in ApiController6.1
  12. CVE-2026-27467BigBlueButton: Audio from participants to the server initially unmuted2.0
  13. CVE-2026-27466BigBlueButton: Exposed ClamAV port enables Denial of Service7.2
  14. CVE-2025-61602BigBlueButton vulnerable to Chat DoS via invalid reactionEmojiId7.5
  15. CVE-2025-61601BigBlueButton vulnerable to DoS via PollSubmitVote GraphQL mutation7.5

The record

Peak rank
#34 in Oct 2020
Busiest month shown
Oct 2020, 15 CVEs
Months with a KEV entry
0 since Oct 2020
Monthly snapshots
5 since 2020
Bigbluebutton's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store