📦 Bigbluebutton

by Bigbluebutton

🔍 What is Bigbluebutton?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-27605

CRITICAL CVSS 9.8 Oct 21, 2020

CVE-2020-27605 is a critical vulnerability in BigBlueButton that allows remote code execution through malicious EPS files. Attackers can exploit Ghostscript's weak sandbox to execute arbitrary code on...

CVE-2025-61602

HIGH CVSS 7.5 Oct 9, 2025

This vulnerability allows any authenticated user in a BigBlueButton virtual classroom meeting to crash the chat functionality for all participants by sending a malformed reactionEmojiId in a GraphQL m...

CVE-2022-29169

HIGH CVSS 7.5 Jun 1, 2022

BigBlueButton web conferencing systems are vulnerable to regular expression denial of service (ReDoS) attacks through malicious User-Agent headers. Attackers can send specially crafted requests contai...

CVE-2026-27467

LOW CVSS 2.0 Feb 21, 2026

BigBlueButton versions 3.0.19 and below have a vulnerability where clients send audio to the server even when muted during initial session join. While the server discards this audio from being heard b...